HP Software Distributor Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1016139
|
|
SecurityTracker URL: http://securitytracker.com/id?1016139
|
|
CVE Reference: CVE-2006-2574
(Links to External Site)
|
Updated: Sep 5 2009
|
Original Entry Date: May 23 2006
|
Impact: User access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: HP Security Bulletin
|
Description: A vulnerability was reported in HP Software Distributor on HP-UX. A local user can gain elevated privileges.
The application contains unspecified vulnerabilities. No details were provided.
HP credits NCC Group with reporting this vulnerability.
|
Impact: A local user can gain elevated privileges.
|
Solution: The vendor has issued the following fixes, available at:
http://itrc.hp.com
HP-UX B.11.23
B.11.23.0606.045 or subsequent
HP-UX
B.11.11
PHCO_34539 or subsequent
HP-UX B11.04
PHCO_34814 or subsequent
HP-UX B.11.00
PHCO_34568 or subsequent
The
HP advisory is available at:
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00659649
|
Vendor URL: www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00659649 (Links to External Site)
|
Cause: Not specified
|
Underlying OS: UNIX (HP/UX)
|
Underlying OS Comments: B.11.00, B.11.04, B.11.11, B.11.23
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 23 May 2006 08:38:39 -0400
Subject: HPSBUX02114 SSRT061115 rev.1 - HP-UX Running Software Distributor Local Elevation of Privilege
|
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00659649
|
|