First published: Thu Aug 01 2002(Updated: )
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Tru64 | =4.0g | |
HP Tru64 | =5.0a | |
HP Tru64 | =5.1af | |
HP Tru64 | =4.0f | |
HP Tru64 | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1616 is considered critical due to multiple buffer overflows that allow local users to gain root privileges.
To fix CVE-2002-1616, you should apply the latest security patches available for the affected versions of HP Tru64 UNIX.
CVE-2002-1616 affects HP Tru64 UNIX versions 4.0g, 4.0f, 5.0a, 5.1, and 5.1a.
Exploiting CVE-2002-1616 can lead to unauthorized local access, allowing attackers to execute arbitrary code with root privileges.
A possible workaround for CVE-2002-1616 is to restrict local user access to vulnerable commands until patches can be applied.