VYPR
Unrated severityNVD Advisory· Published Sep 2, 2002· Updated Apr 16, 2026

CVE-2002-1604

CVE-2002-1604

Description

Multiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variable to (1) csh, (2) dtsession, (3) dxsysinfo, (4) imapd, (5) inc, (6) uucp, (7) uux, (8) rdist, or (9) deliver.

Affected products

10
  • HP/Hpux5 versions
    cpe:2.3:o:hp:hp-ux:10.20:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:hp:hp-ux:10.20:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:hp-ux:11.04:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:hp-ux:11.22:*:*:*:*:*:*:*
  • HP/Tru645 versions
    cpe:2.3:o:hp:tru64:4.0f:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:hp:tru64:4.0f:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:tru64:4.0g:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:tru64:5.0a:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:tru64:5.1:*:*:*:*:*:*:*
    • cpe:2.3:o:hp:tru64:5.1a:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.