Tru64 passwd Local Privilege Escalation Vulnerability
BID:5380
Info
Tru64 passwd Local Privilege Escalation Vulnerability
| Bugtraq ID: | 5380 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 01 2002 12:00AM |
| Updated: | Aug 01 2002 12:00AM |
| Credit: | Published in a Compaq security advisory. |
| Vulnerable: |
Compaq Tru64 5.1 a Compaq Tru64 5.1 Compaq Tru64 5.0 a Compaq Tru64 4.0 g Compaq Tru64 4.0 f |
| Not Vulnerable: | |
Discussion
Tru64 passwd Local Privilege Escalation Vulnerability
Tru64 is a Unix variant. passwd is a Unix utility which may be used to change the password of the current user.
A vulnerability has been reported in the version of passwd included with some releases of Tru64. A local user may be able to exploit this vulnerability to gain root privileges on the vulnerable system. Full details on this issue are not currently available.
Tru64 is a Unix variant. passwd is a Unix utility which may be used to change the password of the current user.
A vulnerability has been reported in the version of passwd included with some releases of Tru64. A local user may be able to exploit this vulnerability to gain root privileges on the vulnerable system. Full details on this issue are not currently available.
Exploit / POC
Tru64 passwd Local Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Tru64 passwd Local Privilege Escalation Vulnerability
Solution:
Patches are available:
Compaq Tru64 4.0 g
Compaq Tru64 4.0 f
Compaq Tru64 5.0 a
Compaq Tru64 5.1
Compaq Tru64 5.1 a
Solution:
Patches are available:
Compaq Tru64 4.0 g
-
Compaq t64v40gb17-c0010404-14948-es-20020730.tar
http://ftp.support.compaq.com/patches/public/unix/v4.0g/t64v40gb17-c00 10404-14948-es-20020730.tar
Compaq Tru64 4.0 f
-
Compaq duv40fb18-c0067403-14947-es-20020730.tar
http://ftp.support.compaq.com/patches/public/unix/v4.0f/duv40fb18-c006 7403-14947-es-20020730.tar
Compaq Tru64 5.0 a
-
Compaq t64v50ab17-c0018404-14949-es-20020730.tar
http://ftp.support.compaq.com/patches/public/unix/v5.0a/t64v50ab17-c00 18404-14949-es-20020730.tar
Compaq Tru64 5.1
-
Compaq t64v51b19-c0136900-14951-es-20020730.tar
http://ftp.support.compaq.com/patches/public/unix/v5.1/t64v51b19-c0136 900-14951-es-20020730.tar
Compaq Tru64 5.1 a
-
Compaq t64v51ab2-c0041400-14950-es-20020730.tar
http://ftp.support.compaq.com/patches/public/unix/v5.1a/t64v51ab2-c004 1400-14950-es-20020730.tar
References
Tru64 passwd Local Privilege Escalation Vulnerability
References:
References:
- [Tru64 UNIX] V4.0f (SSRT2257) Potential Security Vulnerability Patch (Compaq)
- [Tru64 UNIX] V4.0G (SSRT2257) Potential Security Vulnerability Patch (Compaq)
- [Tru64 UNIX] V5.0a (SSRT2257) Potential Security Vulnerability Patch (Compaq)
- [Tru64 UNIX] V5.1 (SSRT2257) Potential Security Vulnerabilities Patch (Compaq)
- [Tru64 UNIX] V5.1A (SSRT2257) Potential Security Vulnerability Fixes (Compaq)