Vulnerability Name: | CVE-2007-0805 (CCN-32276) | ||||||||
Assigned: | 2007-02-06 | ||||||||
Published: | 2007-02-06 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587. | ||||||||
CVSS v3 Severity: | 2.8 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N) 1.7 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:N/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Feb 06 2007 - 05:44:21 CST PS Information Leak on HP True64 Alpha OSF1 v5.1 1885 Source: MITRE Type: CNA CVE-2007-0805 Source: CCN Type: HP Security Bulletin HPSBTU02179 SSRT061256 HP Tru64 UNIX Running the ps command, Local Disclosure of Sensitive Information Source: HP Type: UNKNOWN HPSBTU02179 Source: CCN Type: HP Tru64 Web site Tru64 UNIX Software Source: FULLDISC Type: UNKNOWN 20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885 Source: OSVDB Type: UNKNOWN 33113 Source: MISC Type: Exploit http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh Source: CCN Type: SA24041 HP Tru64 Process Environment Disclosure Security Issue Source: SECUNIA Type: Vendor Advisory 24041 Source: CCN Type: SA25135 HP Tru64 UNIX "ps" Command Information Disclosure Source: SECUNIA Type: UNKNOWN 25135 Source: CCN Type: SECTRACK ID: 1017592 HP Tru64 UNIX ps Command Discloses Environment Variables to Local Users Source: SECTRACK Type: UNKNOWN 1017592 Source: CCN Type: SECTRACK ID: 1018005 HP Tru64 UNIX ps Command Discloses Potentially Sensitive Information to Local Users Source: CCN Type: OSVDB ID: 33113 HP Tru64 /usr/ucb/ps Arbitrary Process Environment Disclosure Source: CCN Type: OSVDB ID: 35601 HP Tru64 UNIX ps Command Local Information Disclosure Source: BUGTRAQ Type: UNKNOWN 20070206 Re: [Full-disclosure] PS Information Leak on HP Tru64 Alpha OSF1v5.1 1885 Source: BUGTRAQ Type: UNKNOWN 20070206 PS Information Leak on HP True64 Alpha OSF1 v5.1 1885 Source: BUGTRAQ Type: UNKNOWN 20070207 Re: PS Information Leak on HP True64 Alpha OSF1 v5.1 1885 Source: SECTRACK Type: UNKNOWN 1018005 Source: VUPEN Type: UNKNOWN ADV-2007-1654 Source: XF Type: UNKNOWN tru64-ps-information-disclosure(32276) Source: XF Type: UNKNOWN tru64-ps-information-disclosure(32276) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |