|
|
|
Vulnerability Note VU#124352
HP-UX kermit contains local buffer overflow that allows denial-of-service
OverviewThe HP-UX version of kermit contains a buffer overflow that allows local users to prevent other users from running kermit.
I. DescriptionKermit is a file transfer protocol that has been implemented by Hewlett-Packard for use on their systems. On December 21, 2000, HP released a security bulletin regarding a local buffer overflow that affects the kermit client present in HP-UX versions 10.01, 10.10, 10.20, and 11.00.II. ImpactThis vulnerability allows local users to create a denial of service attack that prevents other users from running the kermit program.III. SolutionHP has provided patches for each of the affected versions; please see the vendor section of this document for further details.Systems Affected
References
http://www.securityfocus.com/bid/2170
Credit
This document was written by Jeffrey P. Lanza.
Other Information
| Date Public | 12/21/2000 |
| Date First Published | 01/17/2001 07:17:47 PM |
| Date Last Updated | 07/18/2001 |
| CERT Advisory | |
| CVE Name | CAN-2001-0085 |
| Metric | 0.93 |
| Document Revision | 14 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |