MPE/iX AIFCHANGELOGON Privilege Escalation Vulnerability
BID:6723
Info
MPE/iX AIFCHANGELOGON Privilege Escalation Vulnerability
| Bugtraq ID: | 6723 |
| Class: | Access Validation Error |
| CVE: |
CVE-2001-0608 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 12 2001 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | This vulnerability was reported in an HP security bulletin. |
| Vulnerable: |
HP MPE/iX 6.5 HP MPE/iX 6.0 HP MPE/iX 5.5 |
| Not Vulnerable: | |
Discussion
MPE/iX AIFCHANGELOGON Privilege Escalation Vulnerability
A vulnerability has been discovered in AIF for MPE/iX running on HP3000 systems. Due to a bug in the AIFCHANGELOGON program it may be possible for a malicious local user to access sensitive information and possibly elevate privileges.
Precise technical details regarding this vulnerability are not currently known. This BID will be updated as more information becomes available.
A vulnerability has been discovered in AIF for MPE/iX running on HP3000 systems. Due to a bug in the AIFCHANGELOGON program it may be possible for a malicious local user to access sensitive information and possibly elevate privileges.
Precise technical details regarding this vulnerability are not currently known. This BID will be updated as more information becomes available.
Exploit / POC
MPE/iX AIFCHANGELOGON Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MPE/iX AIFCHANGELOGON Privilege Escalation Vulnerability
Solution:
HP has released an advisory for this issue and fixes have been made available. Information regarding how to obtain fixes is available in the attached advisory.
Solution:
HP has released an advisory for this issue and fixes have been made available. Information regarding how to obtain fixes is available in the attached advisory.