CVE-2004-0952: Medium severity HPE HP-UX vulnerability
HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the addnewclient command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0952?
CVE-2004-0952 has a high severity rating due to the ability for remote attackers to modify data and potentially consume disk space.
What versions of HP-UX are affected by CVE-2004-0952?
CVE-2004-0952 affects HP-UX versions 11.00, 11.11, 11.22, and 11.23.
How do I fix CVE-2004-0952?
To fix CVE-2004-0952, ensure that the TFTP server does not set world-writable permissions on any parts of the directory tree.
What type of attack can exploit CVE-2004-0952?
CVE-2004-0952 can be exploited through remote attacks that leverage the TFTP server's world-writable permissions.
What mitigation strategies are recommended for CVE-2004-0952?
It is recommended to restrict access permissions on the TFTP server directories to prevent unauthorized modifications.