Vulnerabilities > CVE-2003-1097 - Remote Username Flag Local Buffer Overrun vulnerability in HP-UX RExec

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
hp
exploit available

Summary

Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.

Exploit-Db

descriptionHP-UX 10.x/11.x RExec Remote Username Flag Local Buffer Overrun Vulnerability. CVE-2003-1097. Dos exploit for hp-ux platform
idEDB-ID:22552
last seen2016-02-02
modified2003-04-29
published2003-04-29
reporterDavide Del Vecchio
sourcehttps://www.exploit-db.com/download/22552/
titleHP-UX 10.x/11.x RExec Remote Username Flag Local Buffer Overrun Vulnerability

Oval

accepted2008-08-25T04:00:20.623-04:00
classvulnerability
contributors
nameMichael Wood
organizationHewlett-Packard
descriptionBuffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.
familyunix
idoval:org.mitre.oval:def:5611
statusaccepted
submitted2008-07-10T16:22:36.000-04:00
titlePotential buffer overflow in rexec(1)
version35