Operating System - HP-UX
1832730 Members
3189 Online
110043 Solutions
New Discussion

Security Vulnerability in ftpd and ftp

 
Berlene Herren
Honored Contributor

Security Vulnerability in ftpd and ftp


Document ID: HPSBUX0107-162
Date Loaded: 20010718
Title: Security Vulnerability in ftpd and ftp

HEWLETT-PACKARD COMPANY SECURITY BULLETIN: #0162, 19 July '01


PROBLEM: ftpd and ftp incorrectly manage buffers.

PLATFORM: HP9000 Series 700/800 running HP-UX releases 10.01, 10.10, 10.20, 11.00, and 11.11.

DAMAGE: Remote users could execute unauthorized code.

SOLUTION: Install the appropriate patch for HP-UX releases as described below:

10.01 or 10.10 PHNE_23947,
10.20 PHNE_23948,
11.00 PHNE_23949,
11.11 PHNE_23950.

AVAILABILITY: All patches are available now.

CERT Advisory CA-2001-07 references a problem with ftp server glob() funtion implementation. The full text is available at:
http://www.cert.org/advisories/CA-2001-07.html

Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm