vendor:
HP-UX
by:
milw0rm.com
7,2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: HP-UX
Affected Version From: HP-UX 11i
Affected Version To: HP-UX 11i
Patch Exists: YES
Related CWE: N/A
CPE: o:hp:hp-ux
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: HP-UX
2006
HP-UX swpackage buffer overflow exploit
HP-UX 'swpackage' contains an exploitable stack overflow in the handling of command line arguements. Specifically the problem occurs due to insufficent bounds checking in the '-S' optional arguement. 'swpackage' is installed setuid root by default in HP-UX and allows for local root compromise when exploiting this issue.
Mitigation:
Ensure that the 'swpackage' application is not installed with setuid root privileges.