HP-UX Bastille sendmail.cf Information Disclosure Weakness
BID:6878
Info
HP-UX Bastille sendmail.cf Information Disclosure Weakness
| Bugtraq ID: | 6878 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2003 12:00AM |
| Updated: | Feb 13 2003 12:00AM |
| Credit: | This issue was reported in an HP Security Bulletin. |
| Vulnerable: |
Bastille HP-UX Bastille B.02.00.00 |
| Not Vulnerable: |
Bastille HP-UX Bastille B.02.00.05 |
Discussion
HP-UX Bastille sendmail.cf Information Disclosure Weakness
A security weakness has been discovered in version B.02.00.00 of the Bastille Hardening System which may result in information disclosure. This issue occurs when Bastille is used in conjunction with the HP-UX operating system and the Sendmail daemon.
HP has reported that a security weakness still exists in the sendmail.cf even after Bastille has been used to disable the feature.
This issue poses a security threat as it may allow an unauthorized remote attacker to obtain sensitive username and alias information from a target server. As a result a system administrator applying the Bastille system may have a false sense of security as to the confidentiality of system information.
It has been confirmed that Bastille available for the Linux operating system is not affected by this issue.
A security weakness has been discovered in version B.02.00.00 of the Bastille Hardening System which may result in information disclosure. This issue occurs when Bastille is used in conjunction with the HP-UX operating system and the Sendmail daemon.
HP has reported that a security weakness still exists in the sendmail.cf even after Bastille has been used to disable the feature.
This issue poses a security threat as it may allow an unauthorized remote attacker to obtain sensitive username and alias information from a target server. As a result a system administrator applying the Bastille system may have a false sense of security as to the confidentiality of system information.
It has been confirmed that Bastille available for the Linux operating system is not affected by this issue.
Exploit / POC
HP-UX Bastille sendmail.cf Information Disclosure Weakness
No exploit is required.
No exploit is required.
Solution / Fix
HP-UX Bastille sendmail.cf Information Disclosure Weakness
Solution:
A patch has been made available which addresses this issue. Information regarding the patch can be obtained from the attached advisory.
An updated version of Bastille has also been made available. HP-UX users are advised to upgrade as soon as possible.
Bastille HP-UX Bastille B.02.00.00
Solution:
A patch has been made available which addresses this issue. Information regarding the patch can be obtained from the attached advisory.
An updated version of Bastille has also been made available. HP-UX users are advised to upgrade as soon as possible.
Bastille HP-UX Bastille B.02.00.00
-
Bastille Bastille HP-UX B.02.00.05b
http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProdu ctInfo.pl?productNumber=B6849AA
References
HP-UX Bastille sendmail.cf Information Disclosure Weakness
References:
References:
- Bastille Product Page (Bastille)