CVE-2004-2693
Description
HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries have world-writable source files, allowing local privilege escalation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries have world-writable source files, allowing local privilege escalation.
Vulnerability
HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed have insecure directory permissions on files in /opt/gnome/src/GLib/. The source files in this product are world writable after installation [1].
Exploitation
A local authenticated user can modify the world-writable source files in /opt/gnome/src/GLib/. If new libraries are subsequently built from this source, the attacker's modifications may be incorporated, leading to arbitrary code execution when the libraries are loaded. No special authentication beyond a local account is required [1].
Impact
A local attacker who successfully modifies the source files can cause arbitrary code to be executed in the context of any user or service that loads the subsequently built libraries. This can lead to elevated privileges on the system [1].
Mitigation
The bulletin does not provide a specific fix or patch version. HP recommends that after installation, users verify the integrity of the affected files before building libraries from the source. No KEV listing is known. Users should restrict access to the affected directories or remove world-writable permissions on the source files [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:*
- cpe:2.3:o:hp:hp-ux:11.04:*:*:*:*:*:*:*
- cpe:2.3:o:hp:hp-ux:11.11:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.