CVE-2005-3277: Critical severity hpe hp-ux vulnerability
Published Oct 21, 2005
·Updated
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.
Affected Software
3 affected components
HPE HP-UX=11.11
HPE HP-UX=11.00
HPE HP-UX=10.20
Event History
Oct 21, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3277?
CVE-2005-3277 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2005-3277?
To fix CVE-2005-3277, update your HP-UX system to a patched version that resolves this vulnerability.
3
Which versions of HP-UX are affected by CVE-2005-3277?
CVE-2005-3277 affects HP-UX versions 10.20, 11.00, and 11.11.
4
Can CVE-2005-3277 be exploited remotely?
Yes, CVE-2005-3277 can be exploited remotely by attackers using crafted requests.
5
What type of attack does CVE-2005-3277 involve?
CVE-2005-3277 involves an attack that utilizes shell metacharacters in LPD service requests.