0a29.blogspot.com
http://0a29.blogspot.com/2011/12/0a29-11-2-privilege-escalation.html CVE-2011-4834
HP Application Lifestyle Management 11 - 'GetInstalledPackages' Local Privilege Escalation
Record summary
CVE-2011-4834 has a selected CVSS score of 4.6; EIP currently links 1 catalogued exploit.
Description
The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-UX, and Solaris allows local users to gain privileges via (1) a Trojan horse /tmp/tmp.txt FIFO or (2) a symlink attack on /tmp/tmp.txt.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHP Application Lifestyle Management 11 - 'GetInstalledPackages' Local Privilege EscalationExploitDB exploitby anonymousNot analyzed1 file
References
547040Third-party advisory
http://secunia.com/advisories/47040 20111208 0A29-11-2 : Privilege escalation vulnerability in HP Application Lifestyle Management (ALM) Platform v11mailing list
http://www.securityfocus.com/archive/1/520783/100/0/threaded hp-alm-symlink(71698)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/71698 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-4834