Vulnerabilities > CVE-2001-0607 - Denial-Of-Service vulnerability in HP-UX

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
hp

Summary

asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.

Oval

accepted2008-08-25T04:00:21.529-04:00
classvulnerability
contributors
nameMichael Wood
organizationHewlett-Packard
descriptionasecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.
familyunix
idoval:org.mitre.oval:def:5621
statusaccepted
submitted2008-07-10T16:22:36.000-04:00
titleCertain files used by the asecure program have unsafe permissions.
version35