Vulnerabilities > CVE-2006-1689 - Local Unauthorized Access vulnerability in HP Hp-Ux 11.11

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
hp
nessus

Summary

Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access. HP-UX B.11.11: Install PHCO_34545 or later.

Vulnerable Configurations

Part Description Count
OS
Hp
1

Nessus

NASL familyHP-UX Local Security Checks
NASL idHPUX_PHCO_34545.NASL
descriptions700_800 11.11 su(1) cumulative patch : A potential security vulnerability has been identified with su(1) when used with the LDAP netgroup feature. The potential vulnerability could be exploited by a local authorized user to gain unauthorized access.
last seen2020-06-01
modified2020-06-02
plugin id21549
published2006-05-13
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/21549
titleHP-UX PHCO_34545 : HP-UX su(1) Local Unauthorized Access (HPSBUX02111 SSRT061132 rev.2)
code
#
# (C) Tenable Network Security, Inc.
#
# The descriptive text and patch checks in this plugin were 
# extracted from HP patch PHCO_34545. The text itself is
# copyright (C) Hewlett-Packard Development Company, L.P.
#

include("compat.inc");

if (description)
{
  script_id(21549);
  script_version("1.12");
  script_cvs_date("Date: 2018/08/10 18:07:07");

  script_cve_id("CVE-2006-1689");
  script_xref(name:"HP", value:"emr_na-c00637553");
  script_xref(name:"HP", value:"HPSBUX02111");
  script_xref(name:"HP", value:"SSRT061132");

  script_name(english:"HP-UX PHCO_34545 : HP-UX su(1) Local Unauthorized Access (HPSBUX02111 SSRT061132 rev.2)");
  script_summary(english:"Checks for the patch in the swlist output");

  script_set_attribute(
    attribute:"synopsis", 
    value:"The remote HP-UX host is missing a security-related patch."
  );
  script_set_attribute(
    attribute:"description", 
    value:
"s700_800 11.11 su(1) cumulative patch : 

A potential security vulnerability has been identified with su(1) when
used with the LDAP netgroup feature. The potential vulnerability could
be exploited by a local authorized user to gain unauthorized access."
  );
  # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00637553
  script_set_attribute(
    attribute:"see_also",
    value:"http://www.nessus.org/u?bb627f37"
  );
  script_set_attribute(
    attribute:"solution", 
    value:"Install patch PHCO_34545 or subsequent."
  );
  script_set_cvss_base_vector("CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C");

  script_set_attribute(attribute:"plugin_type", value:"local");
  script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux");

  script_set_attribute(attribute:"patch_publication_date", value:"2006/04/03");
  script_set_attribute(attribute:"patch_modification_date", value:"2006/04/07");
  script_set_attribute(attribute:"plugin_publication_date", value:"2006/05/13");
  script_set_attribute(attribute:"vuln_publication_date", value:"2006/04/07");
  script_end_attributes();

  script_category(ACT_GATHER_INFO);
  script_copyright(english:"This script is Copyright (C) 2006-2018 Tenable Network Security, Inc.");
  script_family(english:"HP-UX Local Security Checks");

  script_dependencies("ssh_get_info.nasl");
  script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist");

  exit(0);
}


include("audit.inc");
include("global_settings.inc");
include("hpux.inc");


if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX");
if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING);

if (!hpux_check_ctx(ctx:"11.11"))
{
  exit(0, "The host is not affected since PHCO_34545 applies to a different OS release.");
}

patches = make_list("PHCO_34545");
foreach patch (patches)
{
  if (hpux_installed(app:patch))
  {
    exit(0, "The host is not affected because patch "+patch+" is installed.");
  }
}


flag = 0;
if (hpux_check_patch(app:"OS-Core.CORE-ENG-A-MAN", version:"B.11.11")) flag++;
if (hpux_check_patch(app:"OS-Core.UX-CORE", version:"B.11.11")) flag++;


if (flag)
{
  if (report_verbosity > 0) security_hole(port:0, extra:hpux_report_get());
  else security_hole(0);
  exit(0);
}
else audit(AUDIT_HOST_NOT, "affected");

Oval

accepted2014-03-24T04:00:40.221-04:00
classvulnerability
contributors
  • nameRobert L. Hollis
    organizationThreatGuard, Inc.
  • nameTodd Dolinsky
    organizationOpsware, Inc.
  • nameTodd Dolinsky
    organizationOpsware, Inc.
  • nameMichael Wood
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
descriptionUnspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.
familyunix
idoval:org.mitre.oval:def:1754
statusaccepted
submitted2006-04-06T06:39:00.000-04:00
titleHP-UX su(1) Local Unauthorized Access
version42