Secunia
|
|

|
|
|
|
|
|
|
Release Date: 2007-02-06 Last Update: 2007-02-09 Views: 10,828
Where:
Local system
Impact:
Exposure of sensitive information,
Solution Status:
Unpatched
CVE Reference(s):
Andrea "bunker" Purificato has reported a security issue in HP Tru64, which can be exploited by malicious, local users to gain knowledge of potentially sensitive information.
The security issue is caused due to the "/usr/ucb/ps" command revealing the environment variables and values of all processes to an unprivileged user. This can potentially reveal certain information on processes that belong to the root user.
This is similar to:
SA19426
The vulnerability is reported in HP Tru64 / OSF1 v5.1 1885. Other versions may also be affected.
Solution:
Grant only trusted users access to affected systems.
Provided and/or discovered by:
Andrea "bunker" Purificato
Original Advisory:
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052227.html
Deep Links:
Links available to Secunia VIM customers
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
Subject: HP Tru64 Process Environment Disclosure Security Issue
|
No posts yet |
|
You must be logged in to post a comment. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |