Hewlett-Packard Company Information for VU#203611
inet_network() off-by-one buffer overflow
- Vendor Information Help Date Notified: 17 Jan 2008
- Statement Date:
- Date Updated: 31 Jan 2008
Regarding the ISC report concerning a vulnerability in libbind:
The function inet_network() contains a 1-byte overflow. However,
HP is not affected by this 1-byte overflow in inet_network(), because our
inet_network() API implementation in HP-UX (B.11.11, B.11.23, B.11.31) is
different than other operating systems.
The vendor has not provided us with any further information regarding this vulnerability.
There are no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.