CVE
- Id
- 127
- CVE No.
- CVE-1999-0127
- Status
- Candidate
- Description
- swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.
- Phase
- Proposed (19990623)
- Votes
- ACCEPT(2) Baker, Prosser | MODIFY(1) Frech | NOOP(1) Christey
- Comments
- Frech> (keep current XF: reference, and add) | XF:hpux-sqwmodify | Christey> Perhaps this should be split, per SF-LOC. | Christey> CIAC:H-81 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | HP:HPSBUX9707-064 references CERT:CA-96.27 | http://ciac.llnl.gov/ciac/bulletins/h-81.shtml | | The original AUSCERT advisory says that the programs "create | files in an insecure manner" and "Exploit details involving | this vulnerability have been made publicly available." which | leads one to assume that the following original Bugtraq post | provides the details for a standard symlink problem: | | BUGTRAQ:19961005 swinst,bug | http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419941&w=2