header-logo
Suggest Exploit
vendor:
HP-UX
by:
watercloud
7.5
CVSS
HIGH
Privilege Escalation
CWE
Product Name: HP-UX
Affected Version From:
Affected Version To:
Patch Exists:
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: HP-UX B11.11
2003

HP-UX NLSPATH Privilege Escalation

HP-UX allows the NLSPATH to be set for setuid root programs, which use catopen(3C) and may be executed by other local users. This could result in privilege escalation as an attacker could specify an arbitrary path for a message catalogue, which will be opened with elevated privileges.

Mitigation:

Source

Exploit-DB raw data: