HP-UX kmmodreg Symbolic Link Vulnerability
BID:2821
Info
HP-UX kmmodreg Symbolic Link Vulnerability
| Bugtraq ID: | 2821 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2001-1256 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 04 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | This vulnerability was posted to BugTraq by Graf Potozky <[email protected]> on June 4th, 2001. |
| Vulnerable: |
HP HP-UX (VVOS) 11.0.4 HP HP-UX 11.11 HP HP-UX 11.0 |
| Not Vulnerable: | |
Discussion
HP-UX kmmodreg Symbolic Link Vulnerability
HP-UX is a variant of the UNIX Operating System distributed and maintained by Hewlett Packard. HP-UX is designed for use on systems from small, single-processor servers to enterprise, multiprocessor servers.
A problem with the kmmodreg program used in HP-UX makes it possible for a local user to potentially gain elevated privileges, or deny service to the system. kmmodreg creates symbolic links insecurely, making it possible to overwrite files as root when the system is rebooted.
Therefore, it's possible for a local user to launch a symbolic link attack, potentially denying service to legitimate users, or gaining elevated privileges at the next system reboot.
HP-UX is a variant of the UNIX Operating System distributed and maintained by Hewlett Packard. HP-UX is designed for use on systems from small, single-processor servers to enterprise, multiprocessor servers.
A problem with the kmmodreg program used in HP-UX makes it possible for a local user to potentially gain elevated privileges, or deny service to the system. kmmodreg creates symbolic links insecurely, making it possible to overwrite files as root when the system is rebooted.
Therefore, it's possible for a local user to launch a symbolic link attack, potentially denying service to legitimate users, or gaining elevated privileges at the next system reboot.
Exploit / POC
HP-UX kmmodreg Symbolic Link Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
HP-UX kmmodreg Symbolic Link Vulnerability
Solution:
The vendor has been notified and has supplied a patch to remedy this issue.
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0.4
HP HP-UX 11.11
Solution:
The vendor has been notified and has supplied a patch to remedy this issue.
HP HP-UX 11.0
-
HP PHCO_24112
http://us-support.external.hp.com/common/bin/doc.pl/distrib_redir=0 991759980|* -
HP PHCO_26060
http://itrc.hp.com
HP HP-UX (VVOS) 11.0.4
-
HP PHCO_24197
http://itrc.hp.com
HP HP-UX 11.11
-
HP PHCO_24147
http://itrc.hp.com