HP-UX Vue 3.0 enables local user to obtain root privileges hp-vue (2284) Large Threat
Description:
A vulnerability in Vue in HP-UX methods could enable a neighborhood attacker to achieve superuser privileges.
Consequences:
Gain Privileges
Remedy:
This issue was resolved by two sets of patches from two diverse Hewlett-Packard Security Bulletins:
HPSBUX9404-008: Apply patch PHSS_4055 for HP9000 Sequence 300/400 or patch PHSS_4038 for HP9000 Sequence 700/800. See References. HPSBUX9504-027. Use patch PHSS_4055 for HP9000 Series 300/400 or patch PHSS_4066 for HP9000 Sequence 700/800. See References.
References:
CIAC Information Bulletin E-23b: Vulnerability in HP-UX methods with HP Vue 3.0. Hewlett-Packard Firm Security Bulletin HPSBUX9404-008: Security Vulnerability in Vue 3.0. Hewlett-Packard Business Protection Bulletin HPSBUX9504-027: Safety Vulnerability in HP VUE3.0. (From SecurityFocus archive.) CVE-1999-1134: Vulnerability in Vue three.0 in HP 9.x permits neighborhood end users to gain root privileges,
Office 2010 Professional, as fixed by PHSS_4038,
Windows 7 Ultimate Key, PHSS_4055,
Microsoft Office 2007, and PHSS_4066. CVE-1999-1135: Vulnerability in VUE 3.0 in HP nine.x allows local consumers to realize root privileges, as fixed by PHSS_4994 and PHSS_5438.
Platforms Impacted:
HP HP-UX nine.00 HP HP-UX nine.01 HP HP-UX 9.03 HP HP-UX nine.04 HP HP-UX nine.05 HP HP-UX nine.06 HP HP-UX 9.07 HP HP-UX nine.08 HP HP-UX nine.09 HP HP-UX 9.10
Reported:
Apr 20, 1994
The details inside this database might adjust without notice. Use of this info constitutes acceptance for use in an AS IS issue. There are no warranties,
Office 2010 Professional, implied or otherwise,
Office 2007 Enterprise, regarding this details or its use. Any utilization of this data is with the user's chance. In no celebration shall the author/distributor (IBM Net Protection Systems X-Force) be held liable for just about any damages whatsoever arising out of or in connection with the use or distribute of this information.
For corrections or additions make sure you e mail xforce@iss.net
Return to the primary page