CVE

Id
127  
CVE No.
CVE-1999-0127  
Status
Candidate  
Description
swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.  
Phase
Proposed (19990623)  
Votes
ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | NOOP(1) Christey  
Comments
Frech> (keep current XF: reference, and add) | XF:hpux-sqwmodify | Christey> Perhaps this should be split, per SF-LOC. | Christey> CIAC:H-81 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | HP:HPSBUX9707-064 references CERT:CA-96.27 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | | The original AUSCERT advisory says that the programs "create | files in an insecure manner" and "Exploit details involving | this vulnerability have been made publicly available." which | leads one to assume that the following original Bugtraq post | provides the details for a standard symlink problem: | | BUGTRAQ:19961005 swinst,bug | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419941&w=2