NA

CVE-2003-0090

Published: 15/12/2003 Updated: 07/11/2023

Vulnerability Summary

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2000-0844. Reason: This candidate is a duplicate of CVE-2000-0844. Notes: All CVE users should reference CVE-2000-0844 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

Exploits

/******************************************************************************* * File : x_hp-ux11i_nls_ctc * Usage : cc x_hp-ux11i_nls_ctc -o x_ct ; /x_ct * Purpose : Get a local rootshell from /usr/bin/ct,using HP-UX location language format string bug * Author : watercloud xfocus org * Tested : On HP-UX B1111 *************** ...
source: wwwsecurityfocuscom/bid/8985/info HP-UX allows the NLSPATH to be set for setuid root programs, which use catopen(3C) and may be executed by other local users This could result in privilege escalation as an attacker could specify an arbitrary path for a message catalogue, which will be opened with elevated privileges /********* ...
source: wwwsecurityfocuscom/bid/8985/info HP-UX allows the NLSPATH to be set for setuid root programs, which use catopen(3C) and may be executed by other local users This could result in privilege escalation as an attacker could specify an arbitrary path for a message catalogue, which will be opened with elevated privileges /********** ...