First published: Wed Dec 31 2003(Updated: )
rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =10.30 | |
HPE HP-UX | =11.11 | |
HPE HP-UX | =10.01 | |
HPE HP-UX | =10.00 | |
HPE HP-UX | =10.26 | |
HPE HP-UX | =11.04 | |
HPE HP-UX | =10.34 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =11.0.4 | |
HPE HP-UX | =10.16 | |
HPE HP-UX | =10.20 | |
HPE HP-UX | =10.09 | |
HPE HP-UX | =10.10 | |
HPE HP-UX | =10.24 | |
HPE HP-UX | =11.20 | |
HPE HP-UX | =11.22 | |
HPE HP-UX | =10.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1358 is considered to have high severity due to its potential to allow local users to gain elevated privileges.
To fix CVE-2003-1358, ensure that the PATH environment variable does not include directories writable by unprivileged users.
CVE-2003-1358 affects HP-UX versions 10.00 through 11.22.
CVE-2003-1358 is a local privilege escalation vulnerability and cannot be exploited remotely.
The programs at risk with CVE-2003-1358 include commonly used commands like rm that may be executed with raised privileges.