Vulnerability Description
HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hp | Hp-Ux | 11.00 |
References
- http://marc.info/?l=bugtraq&m=112420609211136&w=2
- http://marc.info/?l=bugtraq&m=112422597529112&w=2
- http://secunia.com/advisories/16456/PatchVendor Advisory
- http://securitytracker.com/id?1014711
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21857
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://marc.info/?l=bugtraq&m=112420609211136&w=2
- http://marc.info/?l=bugtraq&m=112422597529112&w=2
- http://secunia.com/advisories/16456/PatchVendor Advisory
- http://securitytracker.com/id?1014711
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21857
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2004-0952?
CVE-2004-0952 is a vulnerability with a CVSS score of 6.4 (MEDIUM). HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote ...
How severe is CVE-2004-0952?
CVE-2004-0952 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0952?
Check the references section above for vendor advisories and patch information. Affected products include: Hp Hp-Ux.