Vulnerabilities > CVE-2003-1099

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
local
low complexity
hp

Summary

shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.

Vulnerable Configurations

Part Description Count
OS
Hp
3

Oval

accepted2014-03-24T04:01:47.375-04:00
classvulnerability
contributors
  • nameMichael Wood
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
descriptionshar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.
familyunix
idoval:org.mitre.oval:def:5788
statusaccepted
submitted2008-07-08T17:01:38.000-04:00
titleHP-UX Running shar(1), Local Execution of Arbitrary Code
version39