CVE-2002-1616 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 3.9% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-08-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hp | tru64 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Tru64 5 - 'su' Env Local Stack Overflow | 2001-01-26 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/tru64/2002-q3/0019.html
- http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_su.txt
- http://www.kb.cert.org/vuls/id/137555
- http://www.kb.cert.org/vuls/id/177067
- http://www.kb.cert.org/vuls/id/193347
- http://www.kb.cert.org/vuls/id/671627
- http://www.kb.cert.org/vuls/id/864083
- http://www.securityfocus.com/archive/1/290115
- http://www.securityfocus.com/bid/5379
- http://www.securityfocus.com/bid/5380
- http://www.securityfocus.com/bid/5381
- http://www.securityfocus.com/bid/5382
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10614
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11620
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
- http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
→ the Explorer · watch your stack · NVD