Vulnerabilities > CVE-2003-0089 - Local Buffer Overrun vulnerability in HP-UX Software Distributor Lang Environment Variable

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
hp
exploit available

Summary

Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.

Vulnerable Configurations

Part Description Count
OS
Hp
2

Exploit-Db

descriptionHP-UX 11 Software Distributor Lang Environment Variable Local Buffer Overrun Vulnerability. CVE-2003-0089. Local exploit for hp-ux platform
idEDB-ID:23343
last seen2016-02-02
modified2002-12-11
published2002-12-11
reporterwatercloud
sourcehttps://www.exploit-db.com/download/23343/
titleHP-UX 11 Software Distributor Lang Environment Variable Local Buffer Overrun Vulnerability

Oval

accepted2014-03-24T04:01:41.068-04:00
classvulnerability
contributors
  • nameMichael Wood
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
descriptionBuffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.
familyunix
idoval:org.mitre.oval:def:5466
statusaccepted
submitted2008-07-09T16:48:33.000-04:00
titleHP-UX Running Software Distributor (SD), Local Increased Privileges.
version40