First published: Wed Dec 31 2003(Updated: )
Buffer overflow in the setupterm function of (1) lanadmin and (2) landiag programs of HP-UX 10.0 through 10.34 allows local users to execute arbitrary code via a long TERM environment variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =10.30 | |
HPE HP-UX | =10.01 | |
HPE HP-UX | =10.00 | |
HPE HP-UX | =10.26 | |
HPE HP-UX | =10.34 | |
HPE HP-UX | =10.24 | |
HPE HP-UX | =10.08 | |
HPE HP-UX | =10.20 | |
HPE HP-UX | =10.09 | |
HPE HP-UX | =10.10 | |
HPE HP-UX | =10.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1360 is considered to have a high severity due to the potential for local users to execute arbitrary code.
To fix CVE-2003-1360, it is recommended to apply patches provided by HP for the affected versions of HP-UX.
CVE-2003-1360 affects HP-UX versions 10.00 through 10.34.
CVE-2003-1360 is a buffer overflow vulnerability that allows local users to exploit the setupterm function.
CVE-2003-1360 cannot be exploited remotely as it requires local user access.