CVE-2004-0965

Description

stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.

Risk Information

Base Score
7.8
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.059

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities affected in hp-ux 11.23-ia64_64-bitNCM
Multiple Vulnerabilities affected in hp-ux 11.11NCM
Multiple Vulnerabilities affected in hp-ux 11.22NCM
Multiple Vulnerabilities affected in hp-ux 11.00NCM
CVE-2004-0965NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234