Overview
The HP-UX version of kermit contains a buffer overflow that allows local users to prevent other users from running kermit.
Description
Kermit is a file transfer protocol that has been implemented by Hewlett-Packard for use on their systems. On December 21, 2000, HP released a security bulletin regarding a local buffer overflow that affects the kermit client present in HP-UX versions 10.01, 10.10, 10.20, and 11.00. |
Impact
This vulnerability allows local users to create a denial of service attack that prevents other users from running the kermit program. |
Solution
HP has provided patches for each of the affected versions; please see the vendor section of this document for further details. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This document was written by Jeffrey P. Lanza.
Other Information
CVE IDs: | CVE-2001-0085 |
Severity Metric: | 0.93 |
Date Public: | 2000-12-21 |
Date First Published: | 2001-01-18 |
Date Last Updated: | 2001-07-18 20:15 UTC |
Document Revision: | 14 |