Executive Summary

Summary
Title HP Tru64 UNIX Running DNS BIND4/BIND8 as Forwarders: Remote Unauthorized Privileged Access
Informations
Name HPSBTU02095 SSRT051007 First vendor Publication 2006-04-18
Vendor HP Last vendor Modification 2006-04-19
Severity (Vendor) N/A Revision 3

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A potential vulnerability has been identified with the HP Tru64 UNIX operating system running DNS BIND4 or BIND8 when configured as forwarders. The vulnerability could be exploited remotely to gain unauthorized privileged access to the DNS clients.

Original Source

Url : http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00595837

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2

Open Source Vulnerability Database (OSVDB)

Id Description
22888 HP Tru64 UNIX DNS BIND Unspecified Remote Privilege Escalation

HP Tru64 contains a flaw that may allow a malicious user to gain access to unauthorized privileges. An unspecified flaw in the BIND DNS server might allow an attacker to remotely elevate their privileges, potentially leading to a loss of integrity. No further details have been provided.