vendor:
HP-UX 11 ftpd daemon
by:
di0aD
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: HP-UX 11 ftpd daemon
Affected Version From: HP-UX 11 ftpd daemon
Affected Version To: HP-UX 11 ftpd daemon
Patch Exists: YES
Related CWE: N/A
CPE: o:hp:hp-ux
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
HP-UX 11 ftpd daemon Vulnerability
A vulnerability has been discovered in the HP-UX 11 ftpd daemon. The problem can be triggered using the FTP REST command. By specifying a specially calculated numeric argument to the command, it is possible to disclose the contents of that numeric location in process memory. This issue may be exploited to disclose the contents of sensitive files, such as /etc/passwd.
Mitigation:
Upgrade to the latest version of HP-UX 11 ftpd daemon