CVE-2003-1097: Buffer Overflow
Published Dec 31, 2003
·Updated
Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.
Affected Software
12 affected components
HPE HP-UX=10.30
HPE HP-UX=11.11
HPE HP-UX=10.26
HPE HP-UX=11.04
HPE HP-UX=10.34
HPE HP-UX=11.00
HPE HP-UX=10.24
HPE HP-UX=11.22
HPE HP-UX=10.20
HPE HP-UX=10.10
HPE HP-UX=10.16
HPE HP-UX=11.20
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Mar 11, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1097?
The severity of CVE-2003-1097 is considered high due to the potential for local users to gain elevated privileges.
2
How do I fix CVE-2003-1097?
To fix CVE-2003-1097, it is recommended to remove the setuid permissions from the rexec command or apply the relevant patch provided by HP.
3
Which versions of HP-UX are affected by CVE-2003-1097?
CVE-2003-1097 affects HP-UX versions 10.20, 10.24, 10.26, 10.30, 10.34, 11.00, 11.04, 11.11, 11.20, and 11.22.
4
Who can exploit CVE-2003-1097?
Local users with access to the system can exploit CVE-2003-1097 to gain unauthorized root privileges.
5
What components of HP-UX are vulnerable in CVE-2003-1097?
The rexec command in HP-UX when setuid root is the vulnerable component in CVE-2003-1097.