7.2
CVSSv2

CVE-2000-0077

Published: 02/01/2000 Updated: 03/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.

Vulnerable Product Search on Vulmon Subscribe to Product

hp hp-ux 10

hp hp-ux 11

Exploits

# source: wwwsecurityfocuscom/bid/1929/info # # Aserver is a server program that ships with HP-UX versions 10x and above that is used to interface client applications with the audio hardware Because it talks to hardware, it is installed setuid root by default # # During normal execution, Aserver executes "ps" via the system() libcall, ...