Vulnerabilities > CVE-2006-5557 - Local Buffer Overflow vulnerability in HP Hp-Ux 11.00/11.11/11.4

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
hp
exploit available

Summary

Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

Vulnerable Configurations

Part Description Count
OS
Hp
3

Exploit-Db

  • descriptionHP-UX 11i (swmodify) Stack Overflow Local Root Exploit. CVE-2006-5557. Local exploit for hp-ux platform
    fileexploits/hp-ux/local/2634.c
    idEDB-ID:2634
    last seen2016-01-31
    modified2006-10-24
    platformhp-ux
    port
    published2006-10-24
    reporterprdelka
    sourcehttps://www.exploit-db.com/download/2634/
    titleHP-UX 11i swmodify Stack Overflow Local Root Exploit
    typelocal
  • descriptionHP-UX 11i (swpackage) Stack Overflow Local Root Exploit. CVE-2006-5557. Local exploit for hp-ux platform
    fileexploits/hp-ux/local/2633.c
    idEDB-ID:2633
    last seen2016-01-31
    modified2006-10-24
    platformhp-ux
    port
    published2006-10-24
    reporterprdelka
    sourcehttps://www.exploit-db.com/download/2633/
    titleHP-UX 11i swpackage Stack Overflow Local Root Exploit
    typelocal

Oval

accepted2014-03-24T04:01:39.521-04:00
classvulnerability
contributors
  • nameMichael Wood
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
descriptionStack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.
familyunix
idoval:org.mitre.oval:def:5035
statusaccepted
submitted2008-07-08T17:01:37.000-04:00
titleHP-UX Running Software Distributor Local Elevation of Privilege
version40