CVE-2004-1332: Buffer Overflow
Published Dec 31, 2004
·Updated
Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.
Affected Software
15 affected components
HP Hp-ux Series 800=10.20
HP HP-UX=11.11
HP HP-UX=10.01
HP Sis
HP HP-UX=11.23
HP VVOS=10.24
HP HP-UX=11.4
HP Hp-ux Series 700=10.20
HP HP-UX=11.00
HP HP-UX=10.24
HP HP-UX=11.22
HP VVOS=11.04
HP HP-UX=10.20
HP HP-UX=10.10
HP HP-UX=11.11i
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jan 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1332?
CVE-2004-1332 is classified as a high severity vulnerability due to its potential to allow remote execution of arbitrary code.
2
How do I fix CVE-2004-1332?
To fix CVE-2004-1332, disable the FTP daemon's debug option or apply a patch provided by HPE to mitigate the buffer overflow risk.
3
What systems are affected by CVE-2004-1332?
CVE-2004-1332 affects various versions of HP-UX, specifically versions ranging from 10.01 to 11.11i.
4
Can CVE-2004-1332 be exploited remotely?
Yes, CVE-2004-1332 can be exploited remotely via crafted long command requests sent to the FTP daemon.
5
What type of vulnerability is CVE-2004-1332?
CVE-2004-1332 is a stack-based buffer overflow vulnerability impacting the FTP daemon.