CVE-2006-1248: Medium severity HPE HP-UX vulnerability
Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1248?
CVE-2006-1248 has been classified as a moderate severity vulnerability due to its potential impact on file permissions.
How do I fix CVE-2006-1248?
To fix CVE-2006-1248, avoid using usermod with options that set a new home directory without verifying directory permissions first.
Which versions of HP-UX are affected by CVE-2006-1248?
CVE-2006-1248 affects HP-UX versions 11.00, 11.11, and 11.23.
What consequences can arise from CVE-2006-1248?
The consequences of CVE-2006-1248 may include unintentional changes to the ownership of files and directories, leading to insecure file permissions.
Is CVE-2006-1248 a remote vulnerability?
CVE-2006-1248 is not a remote vulnerability; it requires local access to the system to exploit.