HP-UX STMKFONT Local Privilege Escalation Vulnerability
BID:11493
Info
HP-UX STMKFONT Local Privilege Escalation Vulnerability
| Bugtraq ID: | 11493 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 21 2004 12:00AM |
| Updated: | Oct 21 2004 12:00AM |
| Credit: | Discovery is credited to Yang Jilong of NSFOCUS Security Team. |
| Vulnerable: |
HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Avaya Predictive Dialing System (PDS) 12.0 Avaya Predictive Dialing System (PDS) 11.0 Avaya Predictive Dialing System (PDS) 9.0 |
| Not Vulnerable: | |
Discussion
HP-UX STMKFONT Local Privilege Escalation Vulnerability
HP-UX stmkfont is reported prone to a local privilege escalation vulnerability. This issue is due to the handling of paths to external executables by stmkfont, allowing an attacker-specified program to be run with the privileges of stmkfont. stmkfont is typically installed with setgid 'bin' privileges.
All Avaya PDS 9 and 11 platforms are vulnerable to this issue. Avaya PDS 12 platforms running on HP-UX 11.00 are vulnerable as well. PDS 12 versions running on HP-UX 11.11 are not vulnerable.
HP-UX stmkfont is reported prone to a local privilege escalation vulnerability. This issue is due to the handling of paths to external executables by stmkfont, allowing an attacker-specified program to be run with the privileges of stmkfont. stmkfont is typically installed with setgid 'bin' privileges.
All Avaya PDS 9 and 11 platforms are vulnerable to this issue. Avaya PDS 12 platforms running on HP-UX 11.00 are vulnerable as well. PDS 12 versions running on HP-UX 11.11 are not vulnerable.
Exploit / POC
HP-UX STMKFONT Local Privilege Escalation Vulnerability
An exploit is not required to leverage this issue.
An exploit is not required to leverage this issue.
Solution / Fix
HP-UX STMKFONT Local Privilege Escalation Vulnerability
Solution:
HP has released a security bulletin (HPSBUX01088) to address this issue. Please see the referenced bulletin for more information.
Avaya has released an advisory ASA-2005-032 to identify vulnerable versions of Avaya PDS. Avaya recommends applying fixes released by HP to address this issue. Please see the advisory in Web references for more information.
HP HP-UX B.11.11
HP HP-UX B.11.23
HP HP-UX B.11.00
HP HP-UX B.11.22
Solution:
HP has released a security bulletin (HPSBUX01088) to address this issue. Please see the referenced bulletin for more information.
Avaya has released an advisory ASA-2005-032 to identify vulnerable versions of Avaya PDS. Avaya recommends applying fixes released by HP to address this issue. Please see the advisory in Web references for more information.
HP HP-UX B.11.11
-
HP PHSS_31988
http://itrc.hp.com/
HP HP-UX B.11.23
-
HP PHSS_31990
http://itrc.hp.com/
HP HP-UX B.11.00
-
HP PHSS_31987
http://itrc.hp.com/
HP HP-UX B.11.22
-
HP PHSS_31989
http://itrc.hp.com/
References
HP-UX STMKFONT Local Privilege Escalation Vulnerability
References:
References:
- ASA-2005-032 - Update to Hewlett-Packard Security Advisories (Avaya)
- NSFOCUS SA2004-02 : HP-UX stmkfont Local Privilege Escalation Vulnerability (NSFOCUS Security Team
)