Vulnerabilities > CVE-2001-1256 - Symbolic Link vulnerability in HP Hp-Ux 11.00/11.04/11.11

047910
CVSS 1.2 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
high complexity
hp

Summary

kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.

Vulnerable Configurations

Part Description Count
OS
Hp
3

Oval

accepted2014-03-24T04:01:43.510-04:00
classvulnerability
contributors
  • nameMichael Wood
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
descriptionkmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.
familyunix
idoval:org.mitre.oval:def:5628
statusaccepted
submitted2008-07-10T16:22:36.000-04:00
titleHP-UX kmmodreg (1M), Local Denial of Service (DoS), Increased Privilege
version39