vendor:
HP-UX
by:
prdelka
7.5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: HP-UX
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:hp:hp-ux
Platforms Tested: HP-UX 11i
2006
HP-UX swask format string local root exploit
HP-UX 'swask' contains a format string vulnerability. The 'swask' utility is installed setuid root by default. The vulnerability is in the handling of the '-s' optional argument which is passed to a format function as verbatim.
Mitigation:
Update the 'swask' utility to a patched version or remove setuid root permissions.