← Back to CVEs
CVE-2005-3277
N/ADescription
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.
CVE Details
CVSS v3.1 ScoreN/A
Published10/21/2005
Last Modified4/16/2026
Sourcenvd
Honeypot Sightings0
Affected Products
hp:hp-ux
References
http://archives.neohapsis.com/archives/hp/2002-q3/0064.html(cve@mitre.org)
http://www.frsirt.com/exploits/20051019.hpux_lpd_exec.pm.php(cve@mitre.org)
http://www.securityfocus.com/bid/15136(cve@mitre.org)
http://archives.neohapsis.com/archives/hp/2002-q3/0064.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.frsirt.com/exploits/20051019.hpux_lpd_exec.pm.php(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/15136(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.