First published: Fri Oct 27 2006(Updated: )
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.11 | |
HPE HP-UX | =11.4 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =11.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5558 is classified as a high severity vulnerability due to its potential to allow local users to execute arbitrary code.
To fix CVE-2006-5558, it is recommended to update HP-UX to a patched version that addresses the format string vulnerability.
CVE-2006-5558 affects HP-UX versions 11.00, 11.11, 11.4, and 11.23.
CVE-2006-5558 is a format string vulnerability.
CVE-2006-5558 is primarily a local vulnerability and requires local user access for exploitation.