|
|
|
Vulnerability Note VU#647438HP-UX FTP daemon is vulnerable to a buffer overflowOverviewThe HP-UX FTP daemon (ftpd) contains a buffer overflow that may allow an unauthenticated, remote attacker to execute arbitrary code.I. DescriptionThe HP-UX FTP daemon (ftpd) is vulnerable to a buffer overflow when the FTP daemon is configured to log debugging information. Debug logging is enabled if the -v flag is present next to the ftpd entry in the inetd.conf (/etc/inetd.conf) configuration file. If an unauthenticated remote attacker supplies the FTP daemon with a specially crafted command, they may be able to trigger a stack-based buffer overflow.Please note that the debug logging option is disabled by default.
HP-UX B.11.00: PHNE_29460 HP-UX B.11.04: PHNE_31034 HP-UX B.11.11: PHNE_29461 HP-UX B.11.22: PHNE_29462 HP customers are encouraged to go to the lT Resource Center to download these patches. Disable Debug Logging The debug logging option is disabled by default. However, if it is enabled, disable it by removing the -v option from the ftpd command within the service inetd.conf configuration file. Systems Affected
References
This vulnerability was reported by iDEFENSE Security. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||