![]() | ![]() |
|
|
Hewlett Packard Information for VU#29823
Vendor StatementHP is vulnerable. Please see:HPSBUX0007-117: Sec. Vulnerability in ftpd, **Rev.01** HEWLETT-PACKARD COMPANY SECURITY ADVISORY: #00117, 11 July '00, Last Revised: 12 July '00 An excerpt:
PLATFORM: HP-UX release 11.00 - Both Problem #1 and #2 below; HP-UX release 10.20 - Problem #2, setproctitle(), only DAMAGE: Unauthorized root access. SOLUTION: Install temporary binary until an official patch is released. AVAILABILITY: The temporary binary is available now (see below). A. Background
ftp://ftp.cup.hp.com/dist/networking/ftp/ftpd.10.20 **Revised 01** --->>>These are to be installed in /usr/lbin/ftpd, with permissions 544. Copyright © 2000 Hewlett-Packard Company Vendor InformationThe vendor has not provided us with any further information regarding this vulnerability.AddendumThe CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||
![]() |
||||||||||||||||||||||