HP-UX Login Restricted Shell Escaping Vulnerability
BID:3068
Info
HP-UX Login Restricted Shell Escaping Vulnerability
| Bugtraq ID: | 3068 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 17 2001 12:00AM |
| Updated: | Jul 17 2001 12:00AM |
| Credit: | This vulnerability was first announced in an HP Security Bulletin on July 17, 2001. |
| Vulnerable: |
HP HP-UX (VVOS) 11.0.4 HP HP-UX (VVOS) 10.24 HP HP-UX 11.11 HP HP-UX 11.0 HP HP-UX 10.26 HP HP-UX 10.20 |
| Not Vulnerable: | |
Discussion
HP-UX Login Restricted Shell Escaping Vulnerability
HP-UX is a the Unix Operating System variant distributed and maintained by Hewlett-Packard.
A problem has been discovered that can allow local users to escape restricted shells. A local user may exploit a hole in login that allows them to escape the restricted environment, traverse the local filesystem, and execute programs on the system at will. Escape of the restricted shell results in access equal to the user's UID (unprivileged).
HP-UX is a the Unix Operating System variant distributed and maintained by Hewlett-Packard.
A problem has been discovered that can allow local users to escape restricted shells. A local user may exploit a hole in login that allows them to escape the restricted environment, traverse the local filesystem, and execute programs on the system at will. Escape of the restricted shell results in access equal to the user's UID (unprivileged).
Solution / Fix
HP-UX Login Restricted Shell Escaping Vulnerability
Solution:
Patches available:
HP HP-UX 10.20
HP HP-UX (VVOS) 10.24
HP HP-UX 10.26
HP HP-UX 11.0
HP HP-UX (VVOS) 11.0.4
HP HP-UX 11.11
Solution:
Patches available:
HP HP-UX 10.20
-
HP PHCO_24267
http://itrc.hp.com
HP HP-UX (VVOS) 10.24
-
HP PHNE_24394
http://itrc.hp.com
HP HP-UX 10.26
-
HP PHCO_24454
http://itrc.hp.com
HP HP-UX 11.0
-
HP PHCO_27721
http://itrc.hp.com
HP HP-UX (VVOS) 11.0.4
-
HP PHCO_24418
http://itrc.hp.com
HP HP-UX 11.11
-
HP PHCO_23900
http://itrc.hp.com