First published: Fri Dec 31 2004(Updated: )
HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.11 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =11.23 | |
HPE HP-UX | =11.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0952 has a high severity rating due to the ability for remote attackers to modify data and potentially consume disk space.
CVE-2004-0952 affects HP-UX versions 11.00, 11.11, 11.22, and 11.23.
To fix CVE-2004-0952, ensure that the TFTP server does not set world-writable permissions on any parts of the directory tree.
CVE-2004-0952 can be exploited through remote attacks that leverage the TFTP server's world-writable permissions.
It is recommended to restrict access permissions on the TFTP server directories to prevent unauthorized modifications.