CVE-1999-0961
CVSS 2.0 Score 6.2 of 10 (medium)
Details
Published Sep 21, 1996
Updated: Nov 20, 2024
Summary
CVE-1999-0961 is a vulnerability affecting HP-UX systems' sysdiag component. This issue permits local users to manipulate log file creation, leading to a symlink attack that grants them root privileges. The vulnerability arises due to insufficient input validation in the sysdiag utility, making it vulnerable to malicious symlink attacks. Successful exploitation allows attackers to escalate their privileges, potentially compromising the entire system. HP released a patch to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- HP-UX
Affected Vendors
- HP