CVE-2001-0379
published 2001-06-18CVE-2001-0379: Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.
PriorityP49medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.53%
41.4th percentile
Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | hp-ux | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f694-qg8r-xm48: Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11
ghsa_unreviewed·2022-04-30
CVE-2001-0379 [MEDIUM] GHSA-f694-qg8r-xm48: Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11
Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.
Red Hat
security flaw
vendor_redhat·2002-05-10·CVSS 7.5
CVE-2002-0379 [HIGH] security flaw
security flaw
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001.315) with legacy RFC 1730 support, and imapd 2000.287 and earlier, allows remote authenticated users to execute arbitrary code via a long BODY request.
No detection rules found.
Exploit-DB
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)
exploitdb·2002-05-10
CVE-2002-0379 WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)
---
// source: https://www.securityfocus.com/bid/4713/info
Wu-imapd is vulnerable to a buffer overflow condition. This has been reported to occur when a valid user requests partial mailbox attributes. Exploitation may result in the execution of arbitrary code as the server process. An attacker may also be able to crash the server, resulting in a denial of service condition.
This only affects versions of imapd with legacy RFC 1730 support, which is disabled by default in imapd 2001.313 and imap-2001.315.
/*
* http://www.freeweb.nu/mantra/05_2002/uw-imapd.html
*
* uw-imapd.c - Remote exploit for uw imapd CAPABILITY IMAP4
*
* Copyright (C) 2002 Christophe "korty" Bailleux
* Copyright (C) 2002 Kostya Kortchinsky
*
*
Exploit-DB
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (2)
exploitdb·2002-05-10
CVE-2002-0379 WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (2)
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (2)
---
// source: https://www.securityfocus.com/bid/4713/info
Wu-imapd is vulnerable to a buffer overflow condition. This has been reported to occur when a valid user requests partial mailbox attributes. Exploitation may result in the execution of arbitrary code as the server process. An attacker may also be able to crash the server, resulting in a denial of service condition.
This only affects versions of imapd with legacy RFC 1730 support, which is disabled by default in imapd 2001.313 and imap-2001.315.
/*
* 0x3a0x29wuim.c - WU-IMAP 2000.287 (linux/i86) remote exploit
*
* dekadish
*
* 0x3a0x29 crew
*
*/
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
#include
http://archives.neohapsis.com/archives/hp/2001-q1/0101.htmlhttp://www.kb.cert.org/vuls/id/249224http://www.osvdb.org/5681https://exchange.xforce.ibmcloud.com/vulnerabilities/6282http://archives.neohapsis.com/archives/hp/2001-q1/0101.htmlhttp://www.kb.cert.org/vuls/id/249224http://www.osvdb.org/5681https://exchange.xforce.ibmcloud.com/vulnerabilities/6282
2001-06-18
Published