7.2
CVSSv2

CVE-2000-1028

Published: 11/12/2000 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 730
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.

Vulnerable Product Search on Vulmon Subscribe to Product

hp hp-ux 11.00

hp hp-ux 9.00

hp hp-ux 9.09

hp hp-ux 9.10

hp hp-ux 9.01

hp hp-ux 9.04

hp hp-ux 9.05

hp hp-ux 9.06

hp hp-ux 10.20

hp hp-ux 9.07

hp hp-ux 9.08

Exploits

source: wwwsecurityfocuscom/bid/1886/info cu is a unix utility that is used for communication between two hosts (usually over phone lines) It is typically isntalled setuid root so that it can access communications hardware when executed by a regular user The version of cu that ships with HP-UX is vulnerable to a buffer overflow attack ...
/* * Copyright (c) 2001 Zorgon * All Rights Reserved * The copyright notice above does not evidence any * actual or intended publication of such source code * * HP-UX /bin/cu exploit * Tested on HP-UX 1100 * zorgon@antionlineorg (wwwnightbirdfreefr) ...