Operating System - HP-UX
1832595 Members
2900 Online
110043 Solutions
New Discussion

Re: CA-2001-21 Buffer Overflow in telnetd

 
Scott Phares
New Member

CA-2001-21 Buffer Overflow in telnetd

I have looked around and cannot locate a fix (patch) for this vulnerability. Has one been issued yet are I am not looking in the right areas? I know that HP is working the problem, but this vulnerability was identified on July 24, 2001. Any help would be greatly appreciated. Thanks much in advance.
Let us be thankful for fools, but for them the rest of use could not succeed
1 REPLY 1
Christopher Caldwell
Honored Contributor

Re: CA-2001-21 Buffer Overflow in telnetd

From
http://www.cert.org/advisories/CA-2001-21.html

Hewlett-Packard Company
...HP-UX 11.X is not vulnerable, HP_UX 10.X is vulnerable. Patches are in process, watch for the associated HP security Bulletin....

(I haven't seen HP's bulletin yet).


Unfortunately, HP doesn't get out security patches as fast as some of us would like. This is especially irritating, since most of the buffer overflow fixes are reasonably trivial. I've been complaining. Perhaps you should too. If enough of complain, maybe they'll speed things up a bit.