CVE-2002-1604
Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.97% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- hp/hp-ux · hp/tru64
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&dt=11
- http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_nlspath.txtExploit
- http://www.kb.cert.org/vuls/id/158499Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/416427Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/437899Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/448987Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/531355Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/567963Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/584243Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/592515Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/846307Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/290115
- http://www.securityfocus.com/bid/5647
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10016
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&dt=11
- http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_nlspath.txtExploit
- http://www.kb.cert.org/vuls/id/158499Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/416427Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/437899Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/448987Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/531355Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/567963Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.