VulnerabilityModified
CVE-2001-1564
setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropped, which could allow local users to cause a denial of service by exhausting available…
LOW 2.1EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
setrlimit in HP-UX 10.01, 10.10, 10.24, 10.20, 11.00, 11.04 and 11.11 does not properly enforce core file size on processes after setuid or setgid privileges are dropped, which could allow local users to cause a denial of service by exhausting available disk space.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 0.49% probability · 40th percentile
- CISA KEV
- Not listed
- Affected
- hp/hp-ux
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/hp/2001-q3/0000.html
- http://www.iss.net/security_center/static/6810.php
- http://www.securityfocus.com/bid/3416
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5159
- http://archives.neohapsis.com/archives/hp/2001-q3/0000.html
- http://www.iss.net/security_center/static/6810.php
- http://www.securityfocus.com/bid/3416
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5159
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.