4.6
CVSSv2

CVE-2006-5557

Published: 27/10/2006 Updated: 19/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 470
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

Vulnerable Product Search on Vulmon Subscribe to Product

hp hp-ux 11.00

hp hp-ux 11.11

hp hp-ux 11.4

Exploits

/* HP-UX swpackage buffer overflow exploit * ======================================= * HP-UX 'swpackage' contains an exploitable stack overflow * in the handling of command line arguements Specifically the * problem occurs due to insufficent bounds checking in the "-S" * optional arguement 'swpackage' is installed setuid root by * default i ...
/* HP-UX swmodify buffer overflow exploit * ======================================= * HP-UX 'swmodify' contains an exploitable stack overflow * in the handling of command line arguements Specifically the * problem occurs due to insufficent bounds checking in the "-S" * optional arguement 'swmodify' is installed setuid root by * default in H ...