HP-UX DCE 'swgentd' Daemon Remote Arbitrary Code Execution Vulnerability
BID:26855
Info
HP-UX DCE 'swgentd' Daemon Remote Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 26855 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6195 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 13 2007 12:00AM |
| Updated: | Dec 18 2007 05:01PM |
| Credit: | Tenable Network Security, working with Zero Day Initiative at TippingPoint is credited with discovering this issue. |
| Vulnerable: |
HP HP-UX B.11.23 HP HP-UX B.11.11 HP DCE-CoreTools 0 HP DCE-Core 0 |
| Not Vulnerable: | |
Discussion
HP-UX DCE 'swgentd' Daemon Remote Arbitrary Code Execution Vulnerability
HP-UX running DCE (Distributed Computing Environment) is prone to a vulnerability that lets remote attackers execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause denial-of-service-conditions.
HP-UX B.11.11 and HP-UX B.11.23 running DCE are vulnerable.
HP-UX running DCE (Distributed Computing Environment) is prone to a vulnerability that lets remote attackers execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause denial-of-service-conditions.
HP-UX B.11.11 and HP-UX B.11.23 running DCE are vulnerable.
Exploit / POC
HP-UX DCE 'swgentd' Daemon Remote Arbitrary Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP-UX DCE 'swgentd' Daemon Remote Arbitrary Code Execution Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the referenced advisory for more information.
HP HP-UX B.11.11
HP HP-UX B.11.23
HP DCE-Core 0
HP DCE-CoreTools 0
Solution:
The vendor has released fixes to address this issue. Please see the referenced advisory for more information.
HP HP-UX B.11.11
-
HP PHSS_36004
HP-UX B.11.11 (11i v1)
http://itrc.hp.com
HP HP-UX B.11.23
-
HP PHSS_36005
HP-UX B.11.23 (11i v2)
http://itrc.hp.com
HP DCE-Core 0
-
HP PHSS_36004
HP-UX B.11.11 (11i v1)
http://itrc.hp.com -
HP PHSS_36005
HP-UX B.11.23 (11i v2)
http://itrc.hp.com
HP DCE-CoreTools 0
-
HP PHSS_36005
HP-UX B.11.23 (11i v2)
http://itrc.hp.com
References
HP-UX DCE 'swgentd' Daemon Remote Arbitrary Code Execution Vulnerability
References:
References: