vendor:
HP-UX X Font Server
by:
watercloud
7.5
CVSS
HIGH
Local Buffer Overflow
119
CWE
Product Name: HP-UX X Font Server
Affected Version From: HP-UX B11.0
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: o:hp:hp-ux:11.0
Platforms Tested: HP-UX B11.0
2003
HP-UX X Font Server Local Buffer Overflow Vulnerability
This vulnerability allows a local attacker to manipulate the execution flow of the vulnerable HP-UX X Font Server application, leading to the execution of arbitrary machine code with the privileges of the 'bin' group. An exploit script is provided to gain a shell with bin group privileges.
Mitigation:
Apply the vendor patches or updates to fix the buffer overflow vulnerability. Additionally, restrict access to the X Font Server to trusted users only.