HP Ignite-UX TFTP File Upload Vulnerability
BID:14571
Info
HP Ignite-UX TFTP File Upload Vulnerability
| Bugtraq ID: | 14571 |
| Class: | Design Error |
| CVE: |
CVE-2004-0952 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovered by Martin O'Neal <[email protected]>. |
| Vulnerable: |
HP Ignite-UX HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 |
| Not Vulnerable: | |
Discussion
HP Ignite-UX TFTP File Upload Vulnerability
During installation, Ignite-UX can use a TFTP server for remote access. Under certain circumstances, parts of the server path can be made world writable. This occurs if the add_new_client command is issued. Remote TFTP clients may be able to then write data to parts of the file system anonymously.
During installation, Ignite-UX can use a TFTP server for remote access. Under certain circumstances, parts of the server path can be made world writable. This occurs if the add_new_client command is issued. Remote TFTP clients may be able to then write data to parts of the file system anonymously.
Exploit / POC
HP Ignite-UX TFTP File Upload Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
HP Ignite-UX TFTP File Upload Vulnerability
Solution:
Apply the HP Ignite-UX version C.6.2.241 patches. HP has made patches available to HP-UX administrators for versions B.11.0, B.11.11, B.11.22, and B.11.23 (patch Ignite-UX_All_C.6.2.241.depot contains fixes for all four) at http://www.hp.com/go/softwaredepot. See the advisory in the reference section for complete details:
HP has updated advisory HPSBUX01219 (SSRT4874 rev.1 - HP-UX Ignite-UX Remote Unauthorized Access) to include manual workarounds to address this issue. Please see the referenced advisory for more information.
HP HP-UX B.11.23
HP HP-UX B.11.11
HP HP-UX B.11.00
HP HP-UX B.11.22
Solution:
Apply the HP Ignite-UX version C.6.2.241 patches. HP has made patches available to HP-UX administrators for versions B.11.0, B.11.11, B.11.22, and B.11.23 (patch Ignite-UX_All_C.6.2.241.depot contains fixes for all four) at http://www.hp.com/go/softwaredepot. See the advisory in the reference section for complete details:
HP has updated advisory HPSBUX01219 (SSRT4874 rev.1 - HP-UX Ignite-UX Remote Unauthorized Access) to include manual workarounds to address this issue. Please see the referenced advisory for more information.
HP HP-UX B.11.23
HP HP-UX B.11.11
HP HP-UX B.11.00
HP HP-UX B.11.22
References
HP Ignite-UX TFTP File Upload Vulnerability
References:
References: