CVE-2004-0965: High severity HPE HP-UX vulnerability
Published Oct 26, 2004
·Updated
stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.
Affected Software
4 affected components
HPE HP-UX=11.11
HPE HP-UX=11.00
HPE HP-UX=11.23
HPE HP-UX=11.22
Remediation
Patch Available
Event History
Oct 26, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0965?
CVE-2004-0965 has a medium severity rating as it allows local users to execute arbitrary code.
2
How do I fix CVE-2004-0965?
To fix CVE-2004-0965, ensure that the PATH environment variable does not include directories that can contain malicious programs.
3
Who is affected by CVE-2004-0965?
CVE-2004-0965 affects users running HP-UX versions 11.00 through 11.23.
4
What software is impacted by CVE-2004-0965?
CVE-2004-0965 impacts the 'stmkfont' command in HP-UX operating systems.
5
Can CVE-2004-0965 be exploited remotely?
CVE-2004-0965 cannot be exploited remotely as it requires local access to the system.