Vulnerability Description
The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Tru64 | 5.1 |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00817515
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052227.html
- http://osvdb.org/33113
- http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.kshExploit
- http://secunia.com/advisories/24041Vendor Advisory
- http://secunia.com/advisories/25135
- http://securitytracker.com/id?1017592
- http://www.securityfocus.com/archive/1/459266/100/0/threaded
- http://www.securityfocus.com/archive/1/459275/100/0/threaded
- http://www.securityfocus.com/archive/1/459593/100/200/threaded
- http://www.securitytracker.com/id?1018005
- http://www.vupen.com/english/advisories/2007/1654
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32276
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00817515
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052227.html
FAQ
What is CVE-2007-0805?
CVE-2007-0805 is a vulnerability with a CVSS score of 2.1 (LOW). The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar...
How severe is CVE-2007-0805?
CVE-2007-0805 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0805?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Tru64.