← Vulnerability feed

Vulnerability record · CVE-2002-1617 · published 31 December 2002

CVE-2002-1617: Hp tru64 vulnerability

Hp · Tru64

Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo, (3) a long -customization argument to dxterm, or (4) a long DISPLAY environment variable to dtterm.

7.2 CVSS 2.0 High EPSS 1.5% · top 26.8%
7.2CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in HP Tru64 UNIX 5.x allow local users to execute arbitrary code via (1) a long -contextDir argument to dtaction, (2) a long -p argument to dtprintinfo, (3) a long -customization argument to dxterm, or (4) a long DISPLAY environment variable to dtterm.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtaction.txt Exploit
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtprintinfo.txt Exploit
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtterm.txt Exploit
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dxterm.txt Exploit
http://www.kb.cert.org/vuls/id/202939 US Government Resource
http://www.kb.cert.org/vuls/id/600699 US Government Resource
http://www.kb.cert.org/vuls/id/836275 US Government Resource
http://www.kb.cert.org/vuls/id/931579 US Government Resource
http://www.securityfocus.com/archive/1/290115 Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtaction.txt Exploit
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtprintinfo.txt Exploit
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dtterm.txt Exploit
http://www.blacksheepnetworks.com/security/hack/tru64/TRU64_dxterm.txt Exploit
http://www.kb.cert.org/vuls/id/202939 US Government Resource
http://www.kb.cert.org/vuls/id/600699 US Government Resource
http://www.kb.cert.org/vuls/id/836275 US Government Resource
http://www.kb.cert.org/vuls/id/931579 US Government Resource
http://www.securityfocus.com/archive/1/290115 Vendor Advisory

Track CVE-2002-1617 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2791Hp tru64 vulnerabilityUnspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecifie…EPSS 6.5%10.0CVE-2003-1496Hp tru64 memory buffer overflow vulnerabilityUnspecified vulnerability in CDE dtmailpr of HP Tru64 4.0F through 5.1B allows local users to gain privileges via unknown attack vectors. NOTE: due t…EPSS 2.3%7.8CVE-2005-3670Hp jetdirect 635n vulnerabilityMultiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running …EPSS 9.1%7.5CVE-2002-1605Hp-ux vulnerabilityBuffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _XKB_CHARSET environment varia…EPSS 13%7.5CVE-2002-1604Hp-ux vulnerabilityMultiple buffer overflows in HP Tru64 UNIX allow local and possibly remote attackers to execute arbitrary code via a long NLSPATH environment variabl…EPSS 15%7.2CVE-2008-4414Hp tru64 permissions and access controls vulnerabilityUnspecified vulnerability in the AdvFS showfile command in HP Tru64 UNIX 5.1B-3 and 5.1B-4 allows local users to gain privileges via unspecified vect…EPSS 0.45%7.2CVE-2007-2553Hp tru64 vulnerabilityUnspecified vulnerability in dop in HP Tru64 UNIX 5.1B-4, 5.1B-3, and 5.1A PK6 allows local users to gain privileges via a large amount of data in th…EPSS 0.94%7.2CVE-2006-6418Hp tru64 memory buffer overflow vulnerabilityBuffer overflow in the POSIX Threads library (libpthread) on HP Tru64 UNIX 4.0F PK8, 4.0G PK4, and 5.1A PK6 allows local users to gain root privilege…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2002-1617), CISA KEV, FIRST EPSS (scores of 2026-10-04). This page is refreshed as NVD updates the record.