Vulnerabilities > CVE-2002-1473 - Denial-Of-Service vulnerability in HP-Ux 10.20/11.00/11.11

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
hp
exploit available
metasploit

Summary

Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code.

Vulnerable Configurations

Part Description Count
OS
Hp
3

Exploit-Db

  • descriptionHP-UX LPD Command Execution. CVE-2002-1473. Remote exploit for hp-ux platform
    idEDB-ID:16927
    last seen2016-02-02
    modified2010-10-06
    published2010-10-06
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16927/
    titleHP-UX LPD Command Execution
  • descriptionHP-UX LPD 10.20, 11.00, 11.11 Command Execution. CVE-2002-1473. Remote exploit for hp-ux platform
    idEDB-ID:10034
    last seen2016-02-01
    modified2002-08-28
    published2002-08-28
    reporterH D Moore
    sourcehttps://www.exploit-db.com/download/10034/
    titleHP-UX LPD 10.20 / 11.00 / 11.11 - Command Execution

Metasploit

descriptionThis exploit abuses an unpublished vulnerability in the HP-UX LPD service. This flaw allows an unauthenticated attacker to execute arbitrary commands with the privileges of the root user. The LPD service is only exploitable when the address of the attacking system can be resolved by the target. This vulnerability was silently patched with the buffer overflow flaws addressed in HP Security Bulletin HPSBUX0208-213.
idMSF:EXPLOIT/HPUX/LPD/CLEANUP_EXEC
last seen2020-05-23
modified2017-07-24
published2006-01-16
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/hpux/lpd/cleanup_exec.rb
titleHP-UX LPD Command Execution