vendor:
HP-UX
by:
watercloud
7.5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: HP-UX
Affected Version From: HP-UX B11.11
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2003-0029
CPE: o:hp:hp-ux:11.11
Platforms Tested: HP-UX B11.11
2003
HP-UX NLSPATH Privilege Escalation Vulnerability
HP-UX allows the NLSPATH to be set for setuid root programs, which use catopen(3C) and may be executed by other local users. This could result in privilege escalation as an attacker could specify an arbitrary path for a message catalogue, which will be opened with elevated privileges.
Mitigation:
Unknown