First published: Tue Nov 18 2003(Updated: )
Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.11 | |
HPE HP-UX | =11.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0089 is classified as a high severity vulnerability due to its potential for local users to execute arbitrary code.
To mitigate CVE-2003-0089, users should update their HP-UX systems to the latest patches provided by Hewlett-Packard.
CVE-2003-0089 affects local users of HP-UX versions B.11.00 and B.11.11.
CVE-2003-0089 is caused by a buffer overflow vulnerability in the Software Distributor utilities when handling long LANG environment variables.
CVE-2003-0089 cannot be exploited remotely as it requires local user access to affected HP-UX systems.