- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: does wu-ftp version 2.6.1 from November 2007 a...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2008 06:58 AM
03-19-2008 06:58 AM
I am being asked to make sure that all my HP-UX servers have been remediated against the RealPath off-by-one buffer over flow vulnerability in wu-ftp that was identified in 2003.
According to the documentation that I found, wu-ftp version 2.6.2 this has been addressed but I cannot find that version available to download from HP.
Does anyone know if the wu-ftp version 2.6.1 from November 2007 that is available from HP addresses this issue? I have glanced through the release notes and cannot find any mention of it.
Attached is a detailed description of the vulernability that I found at the SANS institute site.
Thanks in advance!
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2008 07:44 AM
03-19-2008 07:44 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
It is safe to say the November 2007 release of wu-ftpd included fixes to all known vulnerabilities released in 2003.
In addition, there are several binary fixes to wu-ftpd that are available via ftp via the itrc website or by making a call to the response center.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2008 07:51 AM
03-19-2008 07:51 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
The HP download site for wu-ftp 2.6.1 states that it is for 11.0 and 11.11.
I also have 11.23(PA-RISC) and 11.31 (Itanium) servers. Do you know where I could get version 2.6.1 for those servers?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-19-2008 11:18 AM
03-19-2008 11:18 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
ftp://ftp.wu-ftpd.org/pub/wu-ftpd/
you want to get the wu-ftpd-2.6.2.tar.gz file
or wu-ftpd-2.6.1.tar.gz if ou want all of yoour systems on the save version
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 03:42 AM
03-20-2008 03:42 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
I always get the following response:
Windows cannot access this folder. Make sure you type the file name correctly and that you have permission to access the folder.
Details: Operation timed out
I get that message from clicking on the link in the above response as well as going directly to the http://www.wu-ftpd.org/ site and clicking on the link that they provide there. I also get that response when trying to download from any of the mirror sites close to me.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 06:12 AM
03-20-2008 06:12 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
the link ftp://ftp.wu-ftpd.org/pub/wu-ftpd/
and http://www.wu-ftpd.org
both work for me.
Are you behind a fire wall and do you have your proxy settings set correctly?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 06:17 AM
03-20-2008 06:17 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
I have my HP Account Support Consultant coming on site tomorrow. He has said that he can look into this and get the download for me if it is my proxy settings.
Thanks for your help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 06:49 AM
03-20-2008 06:49 AM
SolutionIf so try this.
1. Start Internet Explorer.
2. On the Tools menu, click Internet Options.
3. Click the Advanced tab, click to clear the Enable folder view for FTP sites check box, click Apply, and then click OK.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 06:53 AM
03-20-2008 06:53 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
Thanks for trying.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 06:55 AM
03-20-2008 06:55 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 07:36 AM
03-20-2008 07:36 AM
Re: does wu-ftp version 2.6.1 from November 2007 address the RealPath vulnerability?
Thanks again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-20-2008 07:38 AM
03-20-2008 07:38 AM