CVE-2000-0972 describes a local file disclosure vulnerability in HP-UX 11.00's crontab utility. A local attacker can read arbitrary files by creating a symbolic link to the target file during a crontab editing session, then quitting to expose the file's contents in error messages. This vulnerability has a CVSS v3.1 score of 5.5 (Medium), indicating a low attack complexity and requiring local user privileges, but allowing for high confidentiality impact. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.00CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.