Vulnerability Name: | CVE-2004-1332 (CCN-18636) | ||||||||
Assigned: | 2004-12-21 | ||||||||
Published: | 2004-12-21 | ||||||||
Updated: | 2017-10-11 | ||||||||
Summary: | Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Hewlett-Packard Security Bulletin HPSBUX01118 SSRT4883 rev.0 - HP-UX ftpd remote privileged access Source: MITRE Type: CNA CVE-2004-1332 Source: HP Type: UNKNOWN HPSBUX01118 Source: CCN Type: SA13608 HP-UX FTP Server Debug Logging Buffer Overflow Vulnerability Source: SECUNIA Type: Patch 13608 Source: CCN Type: SECTRACK ID: 1012650 HP-UX ftpd Debug Logging Buffer Overflow Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1012650 Source: CCN Type: iDEFENSE Security Advisory 12.21.04 Hewlett Packard HP-UX ftpd Remote Buffer Overflow Vulnerability Source: IDEFENSE Type: UNKNOWN 20041221 Hewlett Packard HP-UX ftpd Remote Buffer Overflow Vulnerability Source: CCN Type: US-CERT VU#647438 HP-UX FTP daemon is vulnerable to a buffer overflow Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#647438 Source: CCN Type: OSVDB ID: 12553 HP-UX FTP Server Debug Logging Remote Overflow Source: BID Type: Patch 12077 Source: CCN Type: BID-12077 HP-UX FTP Server Debug Logging Mode Buffer Overflow Vulnerability Source: XF Type: UNKNOWN hp-ftpd-bo(18636) Source: XF Type: UNKNOWN hp-ftpd-bo(18636) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5701 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |