CVE-2007-1993: Buffer Overflow
Published Apr 12, 2007
·Updated
Buffer overflow in the pfsmountd.rpc RPC daemon in the Portable File System (PFS) in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to execute arbitrary code by sending "a call to procedure 5, followed by a crafted payload to procedure 2."
Affected Software
3 affected components
HPE HP-UX=b.11.23
HPE HP-UX=b.11.11
HPE HP-UX=b.11.00
Event History
Apr 12, 2007
CVE Published
10:19 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1993?
CVE-2007-1993 is a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2007-1993?
To fix CVE-2007-1993, update your HP-UX system to the latest patches provided by HPE.
3
What systems are affected by CVE-2007-1993?
CVE-2007-1993 affects HP-UX versions B.11.00, B.11.11, and B.11.23.
4
What kind of attack is possible with CVE-2007-1993?
CVE-2007-1993 allows remote attackers to execute arbitrary code on affected systems.
5
How does CVE-2007-1993 exploit the system?
CVE-2007-1993 exploits the system through a buffer overflow triggered by a crafted RPC payload.