Secunia Security Advisory - A vulnerability has been reported in HP Tru64 UNIX, which can be exploited by malicious, local users to gain escalated privileges.
0f8d73ef55637a41a16b27f6ced3107bc18e8b53de15a6cb9f46b1dd4d95f282
----------------------------------------------------------------------
Do you need accurate and reliable IDS / IPS / AV detection rules?
Get in-depth vulnerability details:
http://secunia.com/binary_analysis/sample_analysis/
----------------------------------------------------------------------
TITLE:
HP Tru64 UNIX AdvFS "showfile" Privilege Escalation Vulnerability
SECUNIA ADVISORY ID:
SA32621
VERIFY ADVISORY:
http://secunia.com/advisories/32621/
CRITICAL:
Less critical
IMPACT:
Privilege escalation
WHERE:
Local system
OPERATING SYSTEM:
HP Tru64 UNIX 5.x
http://secunia.com/advisories/product/2/
DESCRIPTION:
A vulnerability has been reported in HP Tru64 UNIX, which can be
exploited by malicious, local users to gain escalated privileges.
The vulnerability is caused due to an unspecified error within the
AdvFS "showfile" command, which can be exploited to gain escalated
privileges.
The vulnerability is reported in HP Tru64 UNIX version 5.1B-4 and
5.1B-3.
SOLUTION:
Apply ERP kits.
HP Tru64 UNIX v 5.1B-4:
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT1001551-V51BB27-ES-20081015
HP Tru64 UNIX v 5.1B-3:
http://www.itrc.hp.com/service/patch/patchDetail.do?patchid=T64KIT1001540-V51BB26-ES-20080916
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Ilja van Sprundel.
ORIGINAL ADVISORY:
HPSBTU02383 SSRT080098:
http://itrc.hp.com/service/cki/docDisplay.do?docId=c01599842
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------