PT-2007-3338 · Hewlett Packard · Hp-Ux

Published

2007-04-09

·

Updated

2017-10-11

·

CVE-2007-1993

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP-UX versions B.11.00 through B.11.23
Description The issue is related to a buffer overflow in the pfs mountd.rpc RPC daemon within the Portable File System (PFS) in HP-UX. This can be exploited by remote attackers who send a call to procedure 5, followed by a crafted payload to procedure 2, allowing them to execute arbitrary code.
Recommendations For HP-UX versions B.11.00 through B.11.23, consider disabling the pfs mountd.rpc daemon until a patch is available to prevent potential exploitation. Restrict access to the PFS to minimize the risk of arbitrary code execution.

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1993
HPSBUX02203

Affected Products

Hp-Ux