BAC_00698
Note: The BAC v8.06 Service Pack will also resolve the vulnerability.
HISTORY
Version:1 (rev.1) 19 January 20011 Initial release
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For further information, contact normal HP Services support channel.
action: install PHSS_41775 or subsequent
END AFFECTED VERSIONS
HISTORY
Version:1 (rev.1) 19 January 2011 Initial release
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For further information, contact normal HP Services support channel.
Product: ZENphoto
Vendor: www.zenphoto.org
Vulnerable Version: 1.4.2 and probably prior
Tested Version: 1.4.2
Vendor Notification: 18 January 2012
Vendor Patch: 19 January 2012
Public Disclosure: 8 February 2012
Vulnerability Type: PHP Code Execution, SQL Injection, XSS
Solution Status: Fixed by Vendor
Risk Level: High
Credit: High-Tech Bridge SA Security Research Lab ( https://www.htbridge.ch/advisory/ )
PRODUCT SPECIFIC INFORMATION
None
HISTORY
Version:1 (rev.1) - 4 November 2009 Initial release
Version:2 (rev.2) - 19 January 2010 Resolved in HP Power Manager 4.2.10
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For further information, contact normal HP Services support channel.
action: Install revision A.00.09.08s.003 or subsequent
END AFFECTED VERSIONS
HISTORY
Version:1 (rev.1) 19 January 2012 Initial release
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com.
END AFFECTED VERSIONS
HISTORY
Version:1 (rev.1) 1 December 2011 Initial release
Version:2 (rev.2) 14 December 2011 Replaced both unofficial BIND 9.2 depots
Version:3 (rev.3) 19 January 2012 Corrected B.11.23 patch ID typo in AFFECTED VERSIONS
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com.
PRODUCT SPECIFIC INFORMATION
None
HISTORY
Version:1 (rev.1) - 19 January 2010 Initial release
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For further information, contact normal HP Services support channel.
HISTORY
Version:1 (rev.1) 27 October 2011 Initial release
Version:2 (rev.2) 14 December 2011 Added BIND 9.2 solution
Version:3 (rev.3) 14 December 2011 Corrected typo in BIND 9.2 table
Version:4 (rev.4) 19 January 2012 Corrected B.11.23 patch ID typo in AFFECTED VERSIONS
Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com.