Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA447] DSA-447-1 hsftp


Vulnerability Assessment Details

[DSA447] DSA-447-1 hsftp

Vulnerability Assessment Summary
DSA-447-1 hsftp

Detailed Explanation for this Vulnerability Assessment

Ulf Härnhammar from the Debian Security Audit Project
discovered a format string
vulnerability in hsftp. This vulnerability could be exploited by an
attacker able to create files on a remote server with carefully
crafted names, to which a user would connect using hsftp. When the
user requests a directory listing, particular bytes in memory could be
overwritten, potentially permiting arbitrary code to be executed with
the rights of the user invoking hsftp.
Note that while hsftp is installed setuid root, it only uses these
rights to acquire locked memory, and then relinquishes them.
For the current stable distribution (woody) this problem has been
fixed in version 1.11-1woody1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you update your hsftp package.


Solution : http://www.debian.org/security/2004/dsa-447
Network Security Threat Level: High

Networks Security ID: 9715

Vulnerability Assessment Copyright: This script is (C) 2005 Michel Arboi

Cables, Connectors


Juniper Networks EX3300-48P 48-Port PoE+ 4x SFP+ Network Switch w/ Power Cord picture

Juniper Networks EX3300-48P 48-Port PoE+ 4x SFP+ Network Switch w/ Power Cord

$43.95



JUNIPER EX4550-32F-AFO 32-PORT ETHERNET SWITCH 2x POWER SUPPLY - TESTED picture

JUNIPER EX4550-32F-AFO 32-PORT ETHERNET SWITCH 2x POWER SUPPLY - TESTED

$299.99



JUNIPER EX3400-48P 48x 1GB PoE+ RJ-45 4x 10GB SFP+ 2x 40GB QSFP+, DUAL AC POWER picture

JUNIPER EX3400-48P 48x 1GB PoE+ RJ-45 4x 10GB SFP+ 2x 40GB QSFP+, DUAL AC POWER

$210.00



Juniper EX3400-48P 48-Ports PoE+ 4x SFP+ and 2x QSFP+ Managed Switch Tested picture

Juniper EX3400-48P 48-Ports PoE+ 4x SFP+ and 2x QSFP+ Managed Switch Tested

$205.00



Juniper Networks EX2200-C-12P-2G 12 Port Gigabit PoE 2 T/SFP 1G Network Switch picture

Juniper Networks EX2200-C-12P-2G 12 Port Gigabit PoE 2 T/SFP 1G Network Switch

$129.00



Juniper EX3300-48P, 48 Port PoE+ Gigabit Network Switch w/ Power cord picture

Juniper EX3300-48P, 48 Port PoE+ Gigabit Network Switch w/ Power cord

$54.99



EX2300-24P Juniper 24-port 10/100/1000BASE-T PoE+ 4 x 1/10GbE SFP/SFP+ UNCLAIMED picture

EX2300-24P Juniper 24-port 10/100/1000BASE-T PoE+ 4 x 1/10GbE SFP/SFP+ UNCLAIMED

$450.00



Juniper EX2300-C PoE+ 12 Port Rack Mountable Ethernet Switch picture

Juniper EX2300-C PoE+ 12 Port Rack Mountable Ethernet Switch

$200.00



Juniper QFX5100-48T-AFI   48 100M/1G/10G Base-T 6 QSFP AFI picture

Juniper QFX5100-48T-AFI 48 100M/1G/10G Base-T 6 QSFP AFI

$485.00



Juniper EX2300-48P  PoE+ Switch 48x 1GbE & 4 SFP+/SFP 10G uplinks, Tested picture

Juniper EX2300-48P PoE+ Switch 48x 1GbE & 4 SFP+/SFP 10G uplinks, Tested

$289.00



Discussions

No Discussions have been posted on this vulnerability.