Vulnerabilities > CVE-2004-1328 - Newgrp Local Privilege Escalation vulnerability in HP Hp-Ux 11.00/11.11/11.4

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
hp
nessus

Summary

Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.

Vulnerable Configurations

Part Description Count
OS
Hp
3

Nessus

  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHCO_32280.NASL
    descriptions700_800 11.04 (VVOS) libpam, libpam_unix cumulative patch : The remote HP-UX host is affected by multiple vulnerabilities : - A potential security vulnerability has been identified with HP-UX systems where the vulnerability may be exploited to allow a local user to increase privilege. (HPSBUX02091 SSRT061099) - A potential vulnerability has been identified with the HP-UX newgrp(1) command that may allow authorized users to elevate privileges. (HPSBUX01102 SSRT4687)
    last seen2020-06-01
    modified2020-06-02
    plugin id16962
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16962
    titleHP-UX PHCO_32280 : s700_800 11.04 (VVOS) libpam, libpam_unix cumulative patch
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHCO_29682.NASL
    descriptions700_800 11.00 cumulative newgrp(1) patch : A potential vulnerability has been identified with the HP-UX newgrp(1) command that may allow authorized users to elevate privileges.
    last seen2020-06-01
    modified2020-06-02
    plugin id16615
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16615
    titleHP-UX PHCO_29682 : HP-UX Running newgrp(1), Local Privilege Elevation (HPSBUX01102 SSRT4687 rev.2)
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHCO_26385.NASL
    descriptions700_800 11.11 newgrp(1) cumulative patch : A potential vulnerability has been identified with the HP-UX newgrp(1) command that may allow authorized users to elevate privileges.
    last seen2020-06-01
    modified2020-06-02
    plugin id16553
    published2005-02-16
    reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16553
    titleHP-UX PHCO_26385 : HP-UX Running newgrp(1), Local Privilege Elevation (HPSBUX01102 SSRT4687 rev.2)

Oval

accepted2014-03-24T04:01:43.193-04:00
classvulnerability
contributors
  • nameMichael Wood
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
descriptionUnknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.
familyunix
idoval:org.mitre.oval:def:5622
statusaccepted
submitted2008-07-07T16:38:37.000-04:00
titleHP-UX Running newgrp(1), Local Privilege Elevation
version39