PT-2004-1972 · Hewlett Packard · Hp-Ux+2
Martin Oneal
·
Published
2004-12-31
·
Updated
2017-10-11
·
CVE-2004-0952
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
HP-UX versions B.11.00 through B.11.23
Description:
The issue allows remote attackers to modify data or cause disk consumption due to world-writable permissions being set on part of the directory tree by the TFTP server when running Ignite-UX and using the add new client command.
Recommendations:
For HP-UX versions B.11.00 through B.11.23, consider restricting access to the TFTP server or modifying the permissions set by the add new client command to prevent remote attackers from modifying data or causing disk consumption. As a temporary workaround, restrict the use of the add new client command until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux
Ignite-Ux
Tftp Server