Advertisement
Promo

Online business Toolkit

Security hole leaves HP-UX wide open

Wendy McAuliffe ZDNet.co.uk

Published: 19 Oct 2001 17:07 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A remotely exploitable buffer overflow has been detected in HP-UX servers running the telnetd remote access daemon, which could crash the server or allow an intruder to gain root access. The security hole is unique to HP-UX releases 10.X.

The US Computer Incident Advisory Capability (CIAC) has released a high-risk security bulletin about the exploit. The report warns that the vulnerability could allow a hacker to execute arbitrary code with the privileges of the telnetd process.

"Although this vulnerability only applies to some versions of HP-UX, this is not a miniscule market share, as this is one of HP's biggest products," said Graham Cluley, senior technology consultant at the antivirus company Sophos.

The buffer overflow is derived from BSD UNIX source code, and was originally discovered in July. HP this week advised customers running telnetd to install the appropriate patch from its Web site. HP spokespeople were not immediately available for comment.

See ZDNet UK's Enterprise Channel for full coverage.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet news forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
45 out of 99 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters