Vulnerability Name: | CVE-2000-0078 (CCN-3881) | ||||||||
Assigned: | 2000-01-01 | ||||||||
Published: | 2000-01-01 | ||||||||
Updated: | 2018-05-03 | ||||||||
Summary: | The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Jan 02 2000 - 14:49:49 CST HPUX Aserver revisited. Source: MITRE Type: CNA CVE-2000-0005 Source: MITRE Type: CNA CVE-2000-0077 Source: MITRE Type: CNA CVE-2000-0078 Source: CCN Type: Hewlett-Packard Company Security Bulletin HPSBUX0001-108 Security Vulnerability in Aserver (revised) Source: CCN Type: CIAC Information Bulletin K-014 HP-UX Aserver Vulnerability Source: CCN Type: OSVDB ID: 9609 HP-UX aserver -f Argument last_uuid Symlink Privilege Escalation Source: CCN Type: OSVDB ID: 9610 HP-UX 1998 aserver Path Subversion Local Privilege Escalation Source: CCN Type: OSVDB ID: 9611 HP-UX 1999 aserver Path Subversion Local Privilege Escalation Source: CCN Type: BID-1928 HP-UX Aserver /tmp/null Symbolic Link Vulnerability Source: CCN Type: BID-1929 HP-UX Aserver PATH Vulnerability Source: CCN Type: BID-1930 HP-UX Aserver /tmp/last_uuid Symbolic Link Vulnerability Source: XF Type: UNKNOWN hp-aserver(3881) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5728 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |