Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

HP CIFSLogin Buffer Overflow Vulnerability

A vulnerability has been reported in the /opt/cifsclient/bin/cifslogin utility distributed with CIFS/9000. The utility is prone to several buffer overflow conditions and may lead to root compromise.

The vulnerability occurs due to the lack of bounds checking when accepting user input for various commandline options. Specifically, the utility fails to check for excessively long arguments to the following commandline options: '-U', '-D', '-P', '-S', '-N', and '-u'.







 

Privacy Statement
Copyright 2008, SecurityFocus