HP-UX 'useradd' Security Bypass Vulnerability
BID:29286
Info
HP-UX 'useradd' Security Bypass Vulnerability
| Bugtraq ID: | 29286 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1660 |
| Remote: | No |
| Local: | Yes |
| Published: | May 19 2008 12:00AM |
| Updated: | Jun 11 2008 04:22PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Avaya Proactive Contact 3.0 Avaya Proactive Contact 0 Avaya Predictive Dialer (PDS) APC 3.0 Avaya Predictive Dialer 0 |
| Not Vulnerable: | |
Discussion
HP-UX 'useradd' Security Bypass Vulnerability
HP-UX is prone to a security-bypass vulnerability because the software fails to properly restrict access to certain functionality.
Local attackers can exploit this issue to bypass certain security restrictions and carry out some unauthorized tasks. This may lead to various attacks.
This issue affects the following versions of HP-UX:
HP-UX B.11.11
HP-UX B.11.23
HP-UX B.11.31
HP-UX is prone to a security-bypass vulnerability because the software fails to properly restrict access to certain functionality.
Local attackers can exploit this issue to bypass certain security restrictions and carry out some unauthorized tasks. This may lead to various attacks.
This issue affects the following versions of HP-UX:
HP-UX B.11.11
HP-UX B.11.23
HP-UX B.11.31
Exploit / POC
HP-UX 'useradd' Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP-UX 'useradd' Security Bypass Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
HP-UX 'useradd' Security Bypass Vulnerability
References:
References: