ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Security hole leaves HP-UX wide open

Wendy McAuliffe ZDNet.co.uk

Published: 19 Oct 2001 17:07 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A remotely exploitable buffer overflow has been detected in HP-UX servers running the telnetd remote access daemon, which could crash the server or allow an intruder to gain root access. The security hole is unique to HP-UX releases 10.X.

The US Computer Incident Advisory Capability (CIAC) has released a high-risk security bulletin about the exploit. The report warns that the vulnerability could allow a hacker to execute arbitrary code with the privileges of the telnetd process.

"Although this vulnerability only applies to some versions of HP-UX, this is not a miniscule market share, as this is one of HP's biggest products," said Graham Cluley, senior technology consultant at the antivirus company Sophos.

The buffer overflow is derived from BSD UNIX source code, and was originally discovered in July. HP this week advised customers running telnetd to install the appropriate patch from its Web site. HP spokespeople were not immediately available for comment.

See ZDNet UK's Enterprise Channel for full coverage.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet news forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
45 out of 99 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Sybase DBA - Production Support - AAA Banking - Contract

Sybase ASE 12.5 Production support experience - Experience with Solaris / HP-UX operating systems - Sybase ASE installation, configuration and ...

HP-UX SYSTEMS CONSULTANT (HP-UX) SURREY 35K

Your technical ability must include: - HP-UX V11/11I - SUN Solaris - HP/SUN hardware products - Basic SAN knowledge - RedHat Linux (beneficial) In ...

Unix Systems Administrator, AIX / HPUX, W. Yorks

The day to day role will include configuring and monitoring servers HP-UX and server build configuration and best practice, patching, upgrades and ...

Sentry Posts Blog

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment

Please educate your clients!

This extremely short post appeared following a meeting with a decision maker of a potential client. During the conversation I realized that this highly respected and well paid top manager... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains