Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-04-12.1

iDefense Security Advisory 04.12.07 – Remote exploitation of a buffer overflow vulnerability in pfs_mountd.rpc included in multiple versions of Hewlett Packard Co. HP-UX allows for remote root access. If a remote user sends two specially crafted packets over UDP, the buffer overflow is triggered. One must first send a call to procedure 5, and soon thereafter send the actual payload to procedure 2. Due to the closed nature of the pfs_mountd.rpc protocol specification, it is unclear at this time what functions the respective procedures actually perform. iDefense has confirmed the existence of this vulnerability in HP-UX 11.11i. It is suspected that previous versions are also vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55905/04.12.07-1.txt

Source: https://packetstormsecurity.com/files/55905/iDEFENSE-Security-Advisory-2007-04-12.1.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061