PT-2004-1972 · Hewlett Packard · Hp-Ux+2

Martin Oneal

·

Published

2004-12-31

·

Updated

2017-10-11

·

CVE-2004-0952

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions: HP-UX versions B.11.00 through B.11.23
Description: The issue allows remote attackers to modify data or cause disk consumption due to world-writable permissions being set on part of the directory tree by the TFTP server when running Ignite-UX and using the add new client command.
Recommendations: For HP-UX versions B.11.00 through B.11.23, consider restricting access to the TFTP server or modifying the permissions set by the add new client command to prevent remote attackers from modifying data or causing disk consumption. As a temporary workaround, restrict the use of the add new client command until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0952
HPSBUX01219

Affected Products

Hp-Ux
Ignite-Ux
Tftp Server