Oval Definition:oval:org.mitre.oval:def:5788
Revision Date:2014-03-24Version:20
Title:HP-UX Running shar(1), Local Execution of Arbitrary Code
Description:shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-1099
Platform(s):HP-UX 11
Product(s):
Definition Synopsis
  • Criteria meets HP Security Bulletin HPSBUX00304
  • HP-UX B.11.11
  • AND OS-Core.CMDS-AUX is installed
  • AND NOT Patch PHCO_2901 is installed
  • OR Criteria meets HP Security Bulletin HPSBUX00304
  • HP Release B.11.04
  • AND OS-Core.CMDS-AUX is installed
  • AND NOT Patch PHCO_29697 is installed
  • OR Criteria meets HP Security Bulletin HPSBUX00304
  • HP Release B.11.00
  • AND OS-Core.CMDS-AUX is installed
  • AND NOT Patch PHCO_28954 is installed
  • BACK