|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA447] DSA-447-1 hsftp Vulnerability Assessment Details
|
[DSA447] DSA-447-1 hsftp |
||
DSA-447-1 hsftp Detailed Explanation for this Vulnerability Assessment Ulf Härnhammar from the Debian Security Audit Project discovered a format string vulnerability in hsftp. This vulnerability could be exploited by an attacker able to create files on a remote server with carefully crafted names, to which a user would connect using hsftp. When the user requests a directory listing, particular bytes in memory could be overwritten, potentially permiting arbitrary code to be executed with the rights of the user invoking hsftp. Note that while hsftp is installed setuid root, it only uses these rights to acquire locked memory, and then relinquishes them. For the current stable distribution (woody) this problem has been fixed in version 1.11-1woody1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you update your hsftp package. Solution : http://www.debian.org/security/2004/dsa-447 Network Security Threat Level: High Networks Security ID: 9715 Vulnerability Assessment Copyright: This script is (C) 2005 Michel Arboi |
||
Cables, Connectors |
Seagate Exos 7E10 ST2000NM000B 2TB 7200RPM SATA 6.0Gb/s 3.5" Internal Hard Drive
$29.99
Seagate 10TB 7200RPM 12Gbps 3.5in SAS Hard Drive ST10000NM096
$79.99
Dell ST2000NX0403 2T SATA 2.5 inch 7.2K CK3MN server hard drive
$45.00
Toshiba 4TB, SATA 3, 3.5'' Internal Hard Drive (MG03ACA400)
$48.00
HGST Ultrastar DC HC520 12TB SATA 6Gb 256MB 3.5" Enterprise HDD- HUH721212ALE601
$79.99
Seagate ST12000NM0127 12TB 256MB 7200RPM 3.5" SATA 6.0Gb/s Enterprise Hard Drive
$93.88
HGST Ultrastar HE10 HUH721010ALE600 10TB SATA 6Gb/s 7200RPM 3.5" Enterprise HDD
$69.99
Seagate ST12000NM0127 12TB SATA 6Gb/s 256MB 7200RPM 3.5" Enterprise Hard Drive
$99.99
Western Digital WD10JUCT 1TB 2.5" SATA 3Gb/s 5400 RPM 16MB Laptop Hard Drive
$17.98
HGST 0F27352 10TB 3.5" SAS 7200 RPM 12Gb/s Hard Drive 100% #73 v
$65.00
|
||
No Discussions have been posted on this vulnerability. |