HP Distributed Computing Environment Buffer Overrun Vulnerability
BID:9063
Info
HP Distributed Computing Environment Buffer Overrun Vulnerability
| Bugtraq ID: | 9063 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2003 12:00AM |
| Updated: | Nov 17 2003 12:00AM |
| Credit: | Vulnerability announced by HP. |
| Vulnerable: |
HP HP-UX 11.23 HP HP-UX 11.11 HP HP-UX 11.0 Entegrity DCE/DFS for Tru64 Unix 4.3 Entegrity DCE/DFS for Tru64 Unix 4.2.2 Entegrity DCE/DFS for Tru64 Unix 4.2 Entegrity DCE/DFS for Tru64 Unix 4.1.6 Entegrity DCE/DFS for Tru64 Unix 4.1.5 Entegrity DCE/DFS for Tru64 Unix 4.1.4 Compaq OpenVMS 7.3 -2 Alpha Compaq OpenVMS 7.3 -1 Alpha Compaq OpenVMS 7.3 Alpha Compaq OpenVMS 6.2 Alpha |
| Not Vulnerable: | |
Discussion
HP Distributed Computing Environment Buffer Overrun Vulnerability
A problem has been identified in the Distributed Computing Environment (DCE) that may allow attackers to deny service to legitimate users. This issue might also be exploited by a remote attacker to execute arbitrary code on an affected computer.
A problem has been identified in the Distributed Computing Environment (DCE) that may allow attackers to deny service to legitimate users. This issue might also be exploited by a remote attacker to execute arbitrary code on an affected computer.
Exploit / POC
HP Distributed Computing Environment Buffer Overrun Vulnerability
An exploit has been developed to leverage this issue. It is not known to be currently circulating.
An exploit has been developed to leverage this issue. It is not known to be currently circulating.
Solution / Fix
HP Distributed Computing Environment Buffer Overrun Vulnerability
Solution:
HP has released an updated advisory (HPSBUX0311-299 revision 3); this advisory contains patch PHSS_29966 for HP-UX B.11.23 running on Integrity (IA) servers and patch PHSS_30771 for HP-UX B.11.23 running on HP 9000 (PA) servers. Please see the referenced advisory for more information.
HP has released an updated advisory (HPSBOV01056_1 - SSRT4741); this advisory lists HP OpenVMS as a vulnerable platform. Please see the referenced advisory for more information.
HP has released a revised advisory and fixes to address this issue in HP-UX version 11.23.
HP has released fixes and an advisory (HPSBUX0311-299) to address this issue.
HP has released an advisory (SSRT4741 rev.0) to address this issue. Please see the referenced advisory for more information.
HP HP-UX 11.0
HP HP-UX 11.11
HP HP-UX 11.23
Solution:
HP has released an updated advisory (HPSBUX0311-299 revision 3); this advisory contains patch PHSS_29966 for HP-UX B.11.23 running on Integrity (IA) servers and patch PHSS_30771 for HP-UX B.11.23 running on HP 9000 (PA) servers. Please see the referenced advisory for more information.
HP has released an updated advisory (HPSBOV01056_1 - SSRT4741); this advisory lists HP OpenVMS as a vulnerable platform. Please see the referenced advisory for more information.
HP has released a revised advisory and fixes to address this issue in HP-UX version 11.23.
HP has released fixes and an advisory (HPSBUX0311-299) to address this issue.
HP has released an advisory (SSRT4741 rev.0) to address this issue. Please see the referenced advisory for more information.
HP HP-UX 11.0
-
HP PHSS_29963
http://itrc.hp.com
HP HP-UX 11.11
-
HP PHSS_29964
http://itrc.hp.com
HP HP-UX 11.23
-
HP PHSS_29966
http://itrc.hp.com
References
HP Distributed Computing Environment Buffer Overrun Vulnerability
References:
References: