HP Ignite-UX Password File Disclosure Vulnerability
BID:14568
Info
HP Ignite-UX Password File Disclosure Vulnerability
| Bugtraq ID: | 14568 |
| Class: | Design Error |
| CVE: |
CVE-2004-0951 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovered by Martin O'Neal <[email protected]>. |
| Vulnerable: |
HP Ignite-UX HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 |
| Not Vulnerable: |
HP Ignite-UX C.6.0 HP Ignite-UX B.3.2 |
Discussion
HP Ignite-UX Password File Disclosure Vulnerability
During installation, Ignite-UX can use a TFTP server for remote access. Under some circumstances, a copy of the passwd file will be stored in the TFTP server path.
During installation, Ignite-UX can use a TFTP server for remote access. Under some circumstances, a copy of the passwd file will be stored in the TFTP server path.
Exploit / POC
HP Ignite-UX Password File Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
HP Ignite-UX Password File Disclosure Vulnerability
Solution:
Apply the HP Ignite-UX version C.6.2.241 patches. HP has made patches available to HP-UX administrators for versions B.11.0, B.11.11, B.11.22, and B.11.23 (patch Ignite-UX_All_C.6.2.241.depot contains fixes for all four) at http://www.hp.com/go/softwaredepot. See the advisory in the reference section for complete details:
HP HP-UX B.11.23
HP HP-UX B.11.11
HP HP-UX B.11.00
HP HP-UX B.11.22
Solution:
Apply the HP Ignite-UX version C.6.2.241 patches. HP has made patches available to HP-UX administrators for versions B.11.0, B.11.11, B.11.22, and B.11.23 (patch Ignite-UX_All_C.6.2.241.depot contains fixes for all four) at http://www.hp.com/go/softwaredepot. See the advisory in the reference section for complete details:
HP HP-UX B.11.23
HP HP-UX B.11.11
HP HP-UX B.11.00
HP HP-UX B.11.22
References
HP Ignite-UX Password File Disclosure Vulnerability
References:
References: