New User, Welcome!     Login

19 January

[security bulletin] HPSBMA02622 SSRT100342 rev.1 - HP Business Availability Center (BAC) and Business Service Management (BSM), Remote Cross Site Scripting (XSS)

 BAC_00698

Note: The BAC v8.06 Service Pack will also resolve the vulnerability.

HISTORY
Version:1 (rev.1) 19 January 20011 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For further information, contact normal HP Services support channel.


[security bulletin] HPSBUX02623 SSRT100355 rev.1 - HP-UX Running Kerberos, Remote Unauthorized Modification

action: install PHSS_41775 or subsequent

END AFFECTED VERSIONS

HISTORY
Version:1 (rev.1) 19 January 2011 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For further information, contact normal HP Services support channel.


Multiple vulnerabilities in ZENphoto

Product: ZENphoto
Vendor: www.zenphoto.org
Vulnerable Version: 1.4.2 and probably prior
Tested Version: 1.4.2
Vendor Notification: 18 January 2012 
Vendor Patch: 19 January 2012 
Public Disclosure: 8 February 2012 
Vulnerability Type: PHP Code Execution, SQL Injection, XSS
Solution Status: Fixed by Vendor
Risk Level: High 
Credit: High-Tech Bridge SA Security Research Lab ( https://www.htbridge.ch/advisory/ ) 

[security bulletin] HPSBMA02474 SSRT090107 rev.2 - HP Power Manager, Remote Execution of Arbitrary Code

PRODUCT SPECIFIC INFORMATION
None

HISTORY
Version:1 (rev.1) - 4 November 2009 Initial release
Version:2 (rev.2) - 19 January 2010 Resolved in HP Power Manager 4.2.10

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For further information, contact normal HP Services support channel.


[security bulletin] HPSBUX02734 SSRT100729 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Unauthorized Access

action: Install revision A.00.09.08s.003 or subsequent

END AFFECTED VERSIONS

HISTORY
Version:1 (rev.1) 19 January 2012 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel.  For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com.


[security bulletin] HPSBUX02729 SSRT100687 rev.3 - HP-UX Running BIND, Remote Denial of Service (DoS)

END AFFECTED VERSIONS

HISTORY
Version:1 (rev.1) 1 December 2011 Initial release
Version:2 (rev.2) 14 December 2011 Replaced both unofficial BIND 9.2 depots
Version:3 (rev.3) 19 January 2012 Corrected B.11.23 patch ID typo in AFFECTED VERSIONS

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel.  For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com.


[security bulletin] HPSBMA02485 SSRT090252 rev.1 - HP Power Manager, Remote Execution of Arbitrary Code

PRODUCT SPECIFIC INFORMATION
None

HISTORY
Version:1 (rev.1) - 19 January 2010 Initial release

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For further information, contact normal HP Services support channel.


[security bulletin] HPSBUX02719 SSRT100658 rev.4 - HP-UX Running BIND, Remote Denial of Service (DoS)

HISTORY
Version:1 (rev.1) 27 October 2011 Initial release
Version:2 (rev.2) 14 December 2011 Added BIND 9.2 solution
Version:3 (rev.3) 14 December 2011 Corrected typo in BIND 9.2 table
Version:4 (rev.4) 19 January 2012 Corrected B.11.23 patch ID typo in AFFECTED VERSIONS

Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.

Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel.  For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com.




Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!