HP-UX Mkdir Local Unauthorized Access Vulnerability
BID:18748
CVE-2006-3335 |Info
HP-UX Mkdir Local Unauthorized Access Vulnerability
| Bugtraq ID: | 18748 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 30 2006 12:00AM |
| Updated: | Aug 16 2006 08:30PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.04 HP HP-UX B.11.00 Avaya Predictive Dialer 0 |
| Not Vulnerable: | |
Discussion
HP-UX Mkdir Local Unauthorized Access Vulnerability
HP-UX mkdir is prone to a local unauthorized-access vulnerability.
This may facilitate various attacks, including information disclosure and potential code execution, leading to privilege escalation.
HP-UX mkdir is prone to a local unauthorized-access vulnerability.
This may facilitate various attacks, including information disclosure and potential code execution, leading to privilege escalation.
Exploit / POC
HP-UX Mkdir Local Unauthorized Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
HP-UX Mkdir Local Unauthorized Access Vulnerability
Solution:
HP has released an advisory (HPSBUX02128 SSRT5996 - rev.1 HP-UX mkdir(1) Local Unauthorized Access) to address this issue. Please see the references for more information.
HP HP-UX B.11.23
HP HP-UX B.11.04
HP HP-UX B.11.00
Solution:
HP has released an advisory (HPSBUX02128 SSRT5996 - rev.1 HP-UX mkdir(1) Local Unauthorized Access) to address this issue. Please see the references for more information.
HP HP-UX B.11.23
-
HP PHCO_34151
http://itrc.hp.com
HP HP-UX B.11.04
-
HP PHCO_35040
http://itrc.hp.com
HP HP-UX B.11.00
-
HP PHCO_34533
http://itrc.hp.com
References
HP-UX Mkdir Local Unauthorized Access Vulnerability
References:
References: