<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WU-FTPD fb_realpath() Off-By-One Buffer Overflow in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981011#M294367</link>
    <description>I know nothing, but it appears that if I&lt;BR /&gt;wanted to learn anything about "the&lt;BR /&gt;vulnerability", I'd need to do all my own&lt;BR /&gt;research, because you've provided no&lt;BR /&gt;references where I might discover about what&lt;BR /&gt;you're talking.  "[T]he CERT" is a long way&lt;BR /&gt;from a link to a description of "the&lt;BR /&gt;vulnerability".&lt;BR /&gt;&lt;BR /&gt;And while _I_ may know nothing, I may not be&lt;BR /&gt;the only one who's too lazy to go through all&lt;BR /&gt;that duplicative effort.</description>
    <pubDate>Mon, 16 Apr 2007 16:08:58 GMT</pubDate>
    <dc:creator>Steven Schweda</dc:creator>
    <dc:date>2007-04-16T16:08:58Z</dc:date>
    <item>
      <title>WU-FTPD fb_realpath() Off-By-One Buffer Overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981009#M294365</link>
      <description>HP-UX 11iv2 PARISC&lt;BR /&gt;&lt;BR /&gt;Hi all.  I am running wu-ftpd 2.6.1.  I have 2 questions on security of this program.&lt;BR /&gt;&lt;BR /&gt;1. My security-patch check tool doesn't alert me to the vulnerability.  I download a new catalog every nite, so I am wondering why.&lt;BR /&gt;&lt;BR /&gt;2. If I am understanding the CERT correctly, it seems that I have to install 2.6.2 from HP, then run the wu realpath patch from wu.  Has anyone done this, if so, how did it work out?&lt;BR /&gt;&lt;BR /&gt;TIA!</description>
      <pubDate>Fri, 13 Apr 2007 11:26:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981009#M294365</guid>
      <dc:creator>Chrisl_2</dc:creator>
      <dc:date>2007-04-13T11:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: WU-FTPD fb_realpath() Off-By-One Buffer Overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981010#M294366</link>
      <description>Anybody?  If not, I'll close the thread.&lt;BR /&gt;&lt;BR /&gt;TIA</description>
      <pubDate>Mon, 16 Apr 2007 13:01:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981010#M294366</guid>
      <dc:creator>Chrisl_2</dc:creator>
      <dc:date>2007-04-16T13:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: WU-FTPD fb_realpath() Off-By-One Buffer Overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981011#M294367</link>
      <description>I know nothing, but it appears that if I&lt;BR /&gt;wanted to learn anything about "the&lt;BR /&gt;vulnerability", I'd need to do all my own&lt;BR /&gt;research, because you've provided no&lt;BR /&gt;references where I might discover about what&lt;BR /&gt;you're talking.  "[T]he CERT" is a long way&lt;BR /&gt;from a link to a description of "the&lt;BR /&gt;vulnerability".&lt;BR /&gt;&lt;BR /&gt;And while _I_ may know nothing, I may not be&lt;BR /&gt;the only one who's too lazy to go through all&lt;BR /&gt;that duplicative effort.</description>
      <pubDate>Mon, 16 Apr 2007 16:08:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981011#M294367</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2007-04-16T16:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: WU-FTPD fb_realpath() Off-By-One Buffer Overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981012#M294368</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I am also inquiring about this, I use a tool called found stone and it sees this WU-FTPD Off-by-one Buffer overflow vulnerability.&lt;BR /&gt;&lt;BR /&gt;It looks like version 11.0 and 11.1 of HU-UX there is a patch for WU-FTP.&lt;BR /&gt;&lt;BR /&gt;I am running 11.23 on Sparc, any body know where I can get a depot for the latest patch for this?</description>
      <pubDate>Tue, 15 May 2007 12:37:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/wu-ftpd-fb-realpath-off-by-one-buffer-overflow/m-p/3981012#M294368</guid>
      <dc:creator>Jason Haase</dc:creator>
      <dc:date>2007-05-15T12:37:34Z</dc:date>
    </item>
  </channel>
</rss>

