First published: Thu Oct 09 2003(Updated: )
Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-0840 is considered high due to the potential for local users to gain root privileges.
CVE-2003-0840 exploits the system through a buffer overflow caused by a long DISPLAY environment variable.
CVE-2003-0840 affects local users of HP-UX 11.00 and potentially other operating systems.
To fix CVE-2003-0840, it is recommended to limit the length of the DISPLAY environment variable and apply any available patches from HP.
A potential workaround for CVE-2003-0840 is to use a restricted user account that does not have access to set the DISPLAY variable.