CVE-2003-1099: Low severity HPE HP-UX vulnerability
Published Dec 31, 2003
·Updated
shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.
Affected Software
6 affected components
HPE HP-UX=11.11
HPE HP-UX=11.04
HPE HP-UX=11.00
HPE HP-UX=11.00
HPE HP-UX=11.04
HPE HP-UX=11.11
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Mar 11, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1099?
CVE-2003-1099 has a moderate severity level due to its potential to allow local users to conduct a denial of service or execute arbitrary code.
2
How do I fix CVE-2003-1099?
Fixing CVE-2003-1099 involves applying available patches for HP-UX that address the predictable temporary file creation.
3
Who is affected by CVE-2003-1099?
CVE-2003-1099 affects users of HP-UX versions 11.00, 11.04, and 11.11.
4
What type of attack does CVE-2003-1099 enable?
CVE-2003-1099 enables a symlink attack due to the predictable naming of temporary files.
5
Is CVE-2003-1099 a local or remote vulnerability?
CVE-2003-1099 is a local vulnerability that can only be exploited by local users.