J-Security Center

Title: HPUX ftpd User Inputted Format String Stack Overwrite Vulnerability

Severity: HIGH

Description:

A vulnerability exists in the handling of user inputted data in the ftp daemon included by Hewlett-Packard as part of its HPUX operating system. By passing format strings as the argument to the PASS ftp command, it is possible to overwrite values on the stack. Additionally, by passing the proper arguments, it is possible to conduct an attack similar to a traditional buffer overflow.

Affected Products:

  • HP HP-UX 10.20.0
  • HP HP-UX 11.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.