First published: Sun Oct 23 2005(Updated: )
The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HPE HP-UX | =11.11 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =10.20 | |
HPE HP-UX | =10.20 | |
HPE HP-UX | =11.00 | |
HPE HP-UX | =11.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3296 is considered to be a critical vulnerability due to its ability to allow remote attackers to access sensitive directory listings.
To mitigate CVE-2005-3296, apply the latest patches released by HP for the affected versions of HP-UX.
CVE-2005-3296 affects systems running HP-UX versions 10.20, 11.00, and 11.11.
Attackers can use the LIST command in the FTP server to list arbitrary directories as root without authentication.
CVE-2005-3296 was disclosed in October 2005.