First published: Wed Dec 31 2003(Updated: )
Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =10.30 | |
HPE HP-UX | =11.11 | |
HPE HP-UX | =10.26 | |
HPE HP-UX | =11.04 | |
HPE HP-UX | =10.34 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =10.24 | |
HPE HP-UX | =11.22 | |
HPE HP-UX | =10.20 | |
HPE HP-UX | =10.10 | |
HPE HP-UX | =10.16 | |
HPE HP-UX | =11.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2003-1097 is considered high due to the potential for local users to gain elevated privileges.
To fix CVE-2003-1097, it is recommended to remove the setuid permissions from the rexec command or apply the relevant patch provided by HP.
CVE-2003-1097 affects HP-UX versions 10.20, 10.24, 10.26, 10.30, 10.34, 11.00, 11.04, 11.11, 11.20, and 11.22.
Local users with access to the system can exploit CVE-2003-1097 to gain unauthorized root privileges.
The rexec command in HP-UX when setuid root is the vulnerable component in CVE-2003-1097.