Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-02-13.2

iDefense Security Advisory 02.13.07 – Remote exploitation of a design error within Hewlett-Packard’s “SLSd” daemon could allow an attacker to execute privileges as the superuser. The problem specifically exists due to a design error within the “SLSd_daemon” RPC daemon that provides connectivity between the distributed systems. This daemon registers itself under the RPC PROGID of 536870913 or 351456, depending on the HP-UX version. By sending a specially crafted request, the daemon will write attacker supplied data to an arbitrary file as the superuser. iDefense has confirmed the existence of this vulnerability within the “SLSd_daemon” binary as shipped with HP-UX 11.11i and 10.20. All versions are suspected to be vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54425/02.13.07-2.txt

Source: https://packetstormsecurity.com/files/54425/iDEFENSE-Security-Advisory-2007-02-13.2.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.062