CVE-2002-1604: Buffer Overflow
Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1604?
CVE-2002-1604 has a high severity due to its potential to allow local and remote attackers to execute arbitrary code.
How do I fix CVE-2002-1604?
To fix CVE-2002-1604, it is recommended to set environment variables like NLSPATH to safe values and apply any available patches from HP.
Which software versions are affected by CVE-2002-1604?
CVE-2002-1604 affects multiple versions of HP Tru64 UNIX and HP-UX, including versions from 4.0f to 5.1a and various HP-UX versions.
What type of vulnerability is CVE-2002-1604?
CVE-2002-1604 is classified as a buffer overflow vulnerability impacting several HP Tru64 UNIX and HP-UX applications.
Can CVE-2002-1604 be exploited remotely?
Yes, CVE-2002-1604 can potentially be exploited remotely if certain conditions regarding the NLSPATH environment variable are met.