TITLE: HP-UX ftpd Unspecified File Access Vulnerability SECUNIA ADVISORY ID: SA14397 VERIFY ADVISORY: http://secunia.com/advisories/14397/ CRITICAL: Less critical IMPACT: Exposure of system information, Exposure of sensitive information WHERE: >From remote OPERATING SYSTEM: HP-UX 11.x http://secunia.com/product/138/ DESCRIPTION: A vulnerability has been reported in HP-UX, which can be exploited by malicious users to gain knowledge of potentially sensitive information. The vulnerability is caused due to an unspecified error in ftpd allowing users unauthorised access to files on the system. SOLUTION: Apply patches. http://www.itrc.hp.com/service/patch/mainPage.do HP-UX B.11.23: Install PHNE_30983 or subsequent. HP-UX B.11.22: Install PHNE_29462 or subsequent. HP-UX B.11.11: Install PHNE_30990 or subsequent. HP-UX B.11.04: Install PHNE_32813 or subsequent. HP-UX B.11.00: Install PHNE_30989 or subsequent. PROVIDED AND/OR DISCOVERED BY: Reported by vendor. ORIGINAL ADVISORY: SSRT4694: http://itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01119 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------