CVE Vulnerabilities

CVE-2003-1358

Published: Dec 31, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges, which allows local users to gain privileges by modifying the path to point to a malicious rm program.

Affected Software

NameVendorStart VersionEnd Version
Hp-uxHp10.00 (including)10.00 (including)
Hp-uxHp10.01 (including)10.01 (including)
Hp-uxHp10.08 (including)10.08 (including)
Hp-uxHp10.09 (including)10.09 (including)
Hp-uxHp10.10 (including)10.10 (including)
Hp-uxHp10.16 (including)10.16 (including)
Hp-uxHp10.20 (including)10.20 (including)
Hp-uxHp10.24 (including)10.24 (including)
Hp-uxHp10.26 (including)10.26 (including)
Hp-uxHp10.30 (including)10.30 (including)
Hp-uxHp10.34 (including)10.34 (including)
Hp-uxHp11.00 (including)11.00 (including)
Hp-uxHp11.0.4 (including)11.0.4 (including)
Hp-uxHp11.04 (including)11.04 (including)
Hp-uxHp11.11 (including)11.11 (including)
Hp-uxHp11.20 (including)11.20 (including)
Hp-uxHp11.22 (including)11.22 (including)

References