HP-UX FTPD REST Command Memory Disclosure Vulnerability
BID:7825
Info
HP-UX FTPD REST Command Memory Disclosure Vulnerability
| Bugtraq ID: | 7825 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2003 12:00AM |
| Updated: | Jun 05 2003 12:00AM |
| Credit: | Discovery of this issue has been credited to Secure Network Operations. |
| Vulnerable: |
HP HP-UX ftpd 1.1.214 .4 |
| Not Vulnerable: | |
Discussion
HP-UX FTPD REST Command Memory Disclosure Vulnerability
A vulnerability has been discovered in the HP-UX 11 ftpd daemon. The problem can be triggered using the FTP REST command. By specifying a specially calculated numeric argument to the command, it is possible to disclose the contents of that numeric location in process memory. This issue may be exploited to disclose the contents of sensitive files, such as /etc/passwd.
A vulnerability has been discovered in the HP-UX 11 ftpd daemon. The problem can be triggered using the FTP REST command. By specifying a specially calculated numeric argument to the command, it is possible to disclose the contents of that numeric location in process memory. This issue may be exploited to disclose the contents of sensitive files, such as /etc/passwd.