Vulnerabilities > CVE-1999-0333 - Unspecified vulnerability in HP Hp-Ux
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN hp
nessus
Summary
HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.
Nessus
NASL family HP-UX Local Security Checks NASL id HPUX_PHSS_16534.NASL description s700_800 11.X OV OB2.55 patch - WinNT packet : A user can increase privileges or gain invalid access to files on an HP OpenView OmniBack II client host. last seen 2020-06-01 modified 2020-06-02 plugin id 17444 published 2005-03-18 reporter This script is Copyright (C) 2005-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/17444 title HP-UX PHSS_16534 : s700_800 11.X OV OB2.55 patch - WinNT packet code # # (C) Tenable Network Security, Inc. # # The descriptive text and patch checks in this plugin were # extracted from HP patch PHSS_16534. The text itself is # copyright (C) Hewlett-Packard Development Company, L.P. # include("compat.inc"); if (description) { script_id(17444); script_version("$Revision: 1.12 $"); script_cvs_date("$Date: 2013/04/20 00:36:50 $"); script_cve_id("CVE-1999-0333"); script_xref(name:"HP", value:"HPSBUX9810-085"); script_name(english:"HP-UX PHSS_16534 : s700_800 11.X OV OB2.55 patch - WinNT packet"); script_summary(english:"Checks for the patch in the swlist output"); script_set_attribute( attribute:"synopsis", value:"The remote HP-UX host is missing a security-related patch." ); script_set_attribute( attribute:"description", value: "s700_800 11.X OV OB2.55 patch - WinNT packet : A user can increase privileges or gain invalid access to files on an HP OpenView OmniBack II client host." ); script_set_attribute( attribute:"solution", value:"Install patch PHSS_16534 or subsequent." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux"); script_set_attribute(attribute:"patch_publication_date", value:"1998/10/09"); script_set_attribute(attribute:"plugin_publication_date", value:"2005/03/18"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2005-2013 Tenable Network Security, Inc."); script_family(english:"HP-UX Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("hpux.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX"); if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING); if (!hpux_check_ctx(ctx:"11.00")) { exit(0, "The host is not affected since PHSS_16534 applies to a different OS release."); } patches = make_list("PHSS_16534", "PHSS_17310", "PHSS_21637"); foreach patch (patches) { if (hpux_installed(app:patch)) { exit(0, "The host is not affected because patch "+patch+" is installed."); } } flag = 0; if (hpux_check_patch(app:"OMNIBACK-II.OMNI-WIN-P", version:"A.02.55")) flag++; if (flag) { if (report_verbosity > 0) security_hole(port:0, extra:hpux_report_get()); else security_hole(0); exit(0); } else audit(AUDIT_HOST_NOT, "affected");
NASL family HP-UX Local Security Checks NASL id HPUX_PHSS_16474.NASL description s700_800 11.00 OV OB2.55 patch - DA packet : A user can increase privileges or gain invalid access to files on an HP OpenView OmniBack II client host. last seen 2020-06-01 modified 2020-06-02 plugin id 17046 published 2005-02-16 reporter This script is Copyright (C) 2005-2013 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/17046 title HP-UX PHSS_16474 : s700_800 11.00 OV OB2.55 patch - DA packet code # # (C) Tenable Network Security, Inc. # # The descriptive text and patch checks in this plugin were # extracted from HP patch PHSS_16474. The text itself is # copyright (C) Hewlett-Packard Development Company, L.P. # include("compat.inc"); if (description) { script_id(17046); script_version("$Revision: 1.12 $"); script_cvs_date("$Date: 2013/04/20 00:36:50 $"); script_cve_id("CVE-1999-0333"); script_xref(name:"HP", value:"HPSBUX9810-085"); script_name(english:"HP-UX PHSS_16474 : s700_800 11.00 OV OB2.55 patch - DA packet"); script_summary(english:"Checks for the patch in the swlist output"); script_set_attribute( attribute:"synopsis", value:"The remote HP-UX host is missing a security-related patch." ); script_set_attribute( attribute:"description", value: "s700_800 11.00 OV OB2.55 patch - DA packet : A user can increase privileges or gain invalid access to files on an HP OpenView OmniBack II client host." ); script_set_attribute( attribute:"solution", value:"Install patch PHSS_16474 or subsequent." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux"); script_set_attribute(attribute:"patch_publication_date", value:"1998/10/09"); script_set_attribute(attribute:"plugin_publication_date", value:"2005/02/16"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2005-2013 Tenable Network Security, Inc."); script_family(english:"HP-UX Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("hpux.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX"); if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING); if (!hpux_check_ctx(ctx:"11.00")) { exit(0, "The host is not affected since PHSS_16474 applies to a different OS release."); } patches = make_list("PHSS_16474", "PHSS_20385", "PHSS_21326"); foreach patch (patches) { if (hpux_installed(app:patch)) { exit(0, "The host is not affected because patch "+patch+" is installed."); } } flag = 0; if (hpux_check_patch(app:"OMNIBACK-II.OMNI-DA-P", version:"A.02.55")) flag++; if (hpux_check_patch(app:"OMNIBACK-II.OMNI-NOV-P", version:"A.02.55")) flag++; if (flag) { if (report_verbosity > 0) security_hole(port:0, extra:hpux_report_get()); else security_hole(0); exit(0); } else audit(AUDIT_HOST_NOT, "affected");