Description
Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.
Affected products
- HP / hp-ux10.01 – 10.01
- HP / hp-ux10.10 – 10.10
- HP / hp-ux10.20 – 10.20
- HP / hp-ux10.24 – 10.24
- HP / hp-ux11.00 – 11.00
- HP / hp-ux11.4 – 11.4
- HP / hp-ux11.11 – 11.11
- HP / hp-ux11.11i – 11.11i
- HP / hp-ux11.22 – 11.22
- HP / hp-ux11.23 – 11.23
- HP / hp-ux_series_70010.20 – 10.20
- HP / hp-ux_series_80010.20 – 10.20
- HP / sis
- HP / vvos10.24 – 10.24
- HP / vvos11.04 – 11.04
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=110797179710695&w=2
- MISChttp://securitytracker.com/id?1012650
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5701
- MISChttp://www.securityfocus.com/bid/12077
- MAILING_LISThttp://marc.info/?l=bugtraq&m=110797179710695&w=2
- MISChttp://www.kb.cert.org/vuls/id/647438
- VENDOR_ADVISORYhttp://secunia.com/advisories/13608
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/18636
- MISChttp://www.idefense.com/application/poi/display?id=175&type=vulnerabilities&flashstatus=false