vendor:
OSF1
by:
Andrea "bunker" Purificato
5.5
CVSS
MEDIUM
Information Leak
200
CWE
Product Name: OSF1
Affected Version From: OSF1 V5.1 1885 alpha
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: OSF1 V5.1 1885 alpha
Not mentioned
osf1tru64ps.ksh exploit
The "ps" command on HP OSF1 v5.1 Alpha allows unprivileged users to see values of all processes environment variables. This can be used for information discovery.
Mitigation:
Apply the latest patch provided by the vendor.