New User, Welcome!     Login

Next Page >>

install

CA Products That Embed Ingres Multiple Vulnerabilities

Summary: CA products that embed Ingres contain multiple 
vulnerabilities that can allow a remote attacker to execute 
arbitrary code, gain privileges, or cause a denial of service 
condition. These vulnerabilities exist in the products and on the 
platforms listed below. These vulnerabilities do not impact any 
Windows-based Ingres installation. The first vulnerability, 
CVE-2008-3356, allows an unauthenticated attacker to potentially 
set the user and/or group ownership of a verifydb log file to be 
Ingres allowing read/write permissions to both. The second 
vulnerability, CVE-2008-3357, allows an unauthenticated attacker 
to exploit a pointer overwrite vulnerability to execute arbitrary 

HPSBMA02239 SSRT061260 rev.2 - HP OpenView Operations (OVO) Agents Running Shared Trace Service, Remote Arbitrary Code Execution

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP OpenView OVO Agents OVO8.x HTTPS agents on AIX, HP-UX (IA and PA), HP Tru64 Unix, Solaris, and Windows running Shared Trace Service.

BACKGROUND

- -> Note: HP OpenView Operations (OVO) requires HP OpenView Network Node Manager (OV NNM) on the OVO server. OVO will install OV NNM if it is not already present. OV NNM requires the installation of certain patches to be compatible with the resolution discussed below. To insure correct operation the recommendations of Security Bulletin HPSBMA02242 SSRT061260 must be implemented before the recommendations of this Security Bulletin. 

The Hewlett-Packard Company thanks Cody Pierce of TippingPoint DV Labs (dvlabs.tippingpoint.com) for reporting this vulnerability to security-alert@hp.com.

The Hewlett-Packard Company thanks an anonymous researcher working with the iDefense VCP for reporting this vulnerability to security-alert@hp.com. 


[security bulletin] HPSBMA02239 SSRT061260 rev.1 - HP OpenView Operations (OVO) Agents Running Shared Trace Service, Remote Arbitrary Code Execution

The Hewlett-Packard Company thanks Cody Pierce of TippingPoint DV Labs (dvlabs.tippingpoint.com) for reporting this vulnerability to security-alert@hp.com.

The Hewlett-Packard Company thanks an anonymous researcher working with the iDefense VCP for reporting this vulnerability to security-alert@hp.com. 

To determine if a system has an affected version, search the output of "swlist -a revision -l fileset" for an affected fileset. Then determine if the recommended patch or update is installed. 

AFFECTED VERSIONS 

HP-UX B.11.11 
HP-UX B.11.23 

HPSBMA02279 SSRT071298 rev.1 - HP OpenView Configuration Management (CM) Infrastructure (Radia) and Client Configuration Manager (CCM) Running httpd.tkd, Remote Unauthorized Access to Data

HP-UX B.11.00 
HP-UX B.11.11 
HP-UX B.11.23 
============= 
action: install RADINFRAHPUX1_00009 or subsequent 
URL: http://openview.hp.com/ecare/getsupportdoc?docid=RADINFRAHPUX1_00009 

For CM infrastructure (Radia) v4.1

HP-UX B.11.00 

NSOADV-2010-001: Panda Security Local Privilege Escalation

Panda Security for <Product> is the security solution for companies that
need to protect their networks, mainly workstations and file servers.
Panda Security for Business is centrally managed thanks to the
AdminSecure Console, which allows monitoring the entire network,
protecting your critical assets against all types of threats and
optimizing productivity.

(Product description from Panda Website)

This vulnerability is similar to the following vulnerabilities in Panda

[UPDATE] NSOADV-2010-001: Panda Security Local Privilege Escalation

Panda Security for <Product> is the security solution for companies that
need to protect their networks, mainly workstations and file servers.
Panda Security for Business is centrally managed thanks to the
AdminSecure Console, which allows monitoring the entire network,
protecting your critical assets against all types of threats and
optimizing productivity.

(Product description from Panda Website)

This vulnerability is similar to the following vulnerabilities in Panda

[security bulletin] HPSBMA02242 SSRT061260 rev.3 - HP OpenView Network Node Manager (OV NNM) Running Shared Trace Service, Remote Arbitrary Code Execution

 


OV NNM v7.50 
HP-UX (PA)
 Upgrade to NNM v7.51 and install PHSS_36901 or subsequent
 
HP-UX (IA)
 Upgrade to NNM v7.51 and install PHSS_36902 or subsequent
 
Solaris

[security bulletin] HPSBST02329 SSRT080048 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-018 to MS08-025

NOTE: The SMA must have all pertinent SMA Service Packs applied

Windows 2000 Update Rollup 1

Customers are advised to download and install the Windows 2000 Update Rollup 1 for Service Pack 4 on SMA v2.1. For more information please refer to the Windows 2000 Update Rollup 1 for Service Pack 4 and Storage Management Appliance v2.1 advisory at the following website: http://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual&lang=en&cc=us&docIndexId=179111&taskId=101&prodTypeId=12169&prodSeriesId=315667 

Windows 2000 Update Rollup 1 for SP4 does not include security updates released after April 30, 2005 starting from MS05-026. It also does not include patches MS04-003 and MS04-028. Please install these patches in addition to Windows 2000 Update Rollup 1 for SP4, if they have not been installed already

RESOLUTION
HP strongly recommends the immediate installation of all security patches that apply to third party software which is integrated with SMA software products supplied by HP, and that patches are applied in accordance with an appropriate patch management policy.

[security bulletin] HPSBUX01137 SSRT5954 rev.11 - HP-UX Running TCP/IP (IPv4), Remote Denial of Service (DoS)

AFFECTED VERSIONS 

HP-UX B.11.11 
============= 
Networking.NET2-KRN 
action: install PHNE_33159 or subsequent 

HP-UX B.11.22 
============= 
Networking.NET2-KRN 
action: install preliminary binary files per Security Bulletin HPSBUX01164 

[security bulletin] HPSBUX02251 SSRT071449 rev.2 - HP-UX Running BIND, Remote DNS Cache Poisoning

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP-UX B.11.11, B.11.23, B.11.31 running BIND v9.2 or BIND v9.3

BACKGROUND

To determine if a system has an affected version, search the output of "swlist -a revision -l fileset" for an affected fileset. Then determine if the recommended patch or update is installed.

AFFECTED VERSIONS 

For BIND v9.2.0 


VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    has assigned the name CVE-2010-1141 to this issue.

    Steps needed to remediate this vulnerability:

    Guest systems on VMware Workstation, Player, ACE, Server, Fusion
     - Install the remediated version of Workstation, Player, ACE,
       Server and Fusion.
     - Upgrade tools in the virtual machine (virtual machine users
       will be prompted to upgrade).

    Guest systems on ESX 4.0, 3.5, 3.0.3, 2.5.5, ESXi 4.0, 3.5

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    has assigned the name CVE-2010-1141 to this issue.

    Steps needed to remediate this vulnerability:

    Guest systems on VMware Workstation, Player, ACE, Server, Fusion
     - Install the remediated version of Workstation, Player, ACE,
       Server and Fusion.
     - Upgrade tools in the virtual machine (virtual machine users
       will be prompted to upgrade).

    Guest systems on ESX 4.0, 3.5, 3.0.3, 2.5.5, ESXi 4.0, 3.5

[security bulletin] HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-056 to MS08-066

Note: The SMA must have all pertinent SMA Service Packs applied 

Windows 2000 Update Rollup 1

Customers are advised to download and install the Windows 2000 Update Rollup 1 for Service Pack 4 on SMA v2.1. For more information please refer to the Windows 2000 Update Rollup 1 for Service Pack 4 and Storage Management Appliance v2.1 advisory at the following website: http://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual&lang=en&cc=us&docIndexId=179111&taskId=101&prodTypeId=12169&prodSeriesId=315667 

Windows 2000 Update Rollup 1 for SP4 does not include security updates released after April 30, 2005 starting from MS05-026. It also does not include patches MS04-003 and MS04-028. Please install these patches in addition to Windows 2000 Update Rollup 1 for SP4, if they have not been installed already

RESOLUTION
HP strongly recommends the immediate installation of all security patches that apply to third party software which is integrated with SMA software products supplied by HP, and that patches are applied in accordance with an appropriate patch management policy.

HPSBUX02354 SSRT080113 rev.1 - HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)

HP is providing the following software patches to resolve the vulnerability. 
The patches are available from http://www.hp.com/go/softwaredepot/ 
 
HP-UX B.11.11 (11i v1)
 Install update B.06.21.70 or subsequent
 
HP-UX B.11.23 (11i v2)
 Install update B.06.21.70 or subsequent
 
HP-UX B.11.11 (11i v1)

[security bulletin] HPSBUX02351 SSRT080058 rev.3 - HP-UX Running BIND, Remote DNS Cache Poisoning

HP-UX Release - B.11.11 running v9.2.0
BIND Depot name - BIND920v11.depot
 MD5 Sum - F6999280DE19645EF86FF52083AACD72
 
HP-UX Release - B.11.23 running v9.2.0 
Action - Install PHNE_37865

HP-UX Release - B.11.11 running v9.3.2
Action - Install revision C.9.3.2.3.0 or subsequent 
 
HP-UX Release - B.11.23 running v9.3.2

[security bulletin] HPSBUX02351 SSRT080058 rev.4 - HP-UX Running BIND, Remote DNS Cache Poisoning

BIND Depot name -  BIND920v11.depot
MD5 Sum - F6999280DE19645EF86FF52083AACD72
Action - Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf.
 
HP-UX Release - B.11.23 running v9.2.0 
Action - Install PHNE_37865; 
Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf.
 
HP-UX Release - B.11.11 running v9.3.2
Action - Install revision C.9.3.2.3.0 or subsequent; 
Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf. 

[security bulletin] HPSBUX02351 SSRT080058 rev.2 - HP-UX Running BIND, Remote DNS Cache Poisoning

 


The BIND v9.3.2 updates are available for download from http://software.hp.com . 
 
HP-UX Release - B.11.11 running v9.3.2 - Install revision C.9.3.2.3.0 or subsequent 
HP-UX Release - B.11.23 running v9.3.2 - Install revision C.9.3.2.3.0 or subsequent
HP-UX Release - B.11.31 running v9.3.2 - Install revision C.9.3.2.3.0 or subsequent
 

MANUAL ACTIONS: Yes - NonUpdate 

HPSBST02255 SSRT071456 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-042 to MS07-050

NOTE: The SMA must have all pertinent SMA Service Packs applied

Windows 2000 Update Rollup 1

Customers are advised to download and install the Windows 2000 Update Rollup 1 for Service Pack 4 on SMA v2.1. For more information please refer to the Windows 2000 Update Rollup 1 for Service Pack 4 and Storage Management Appliance v2.1 advisory at the following website: http://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual&lang=en&cc=us&docIndexId=179111&taskId=101&prodTypeId=12169&prodSeriesId=315667 

Windows 2000 Update Rollup 1 for SP4 does not include security updates released after April 30, 2005 starting from MS05-026. It also does not include patches MS04-003 and MS04-028. Please install these patches in addition to Windows 2000 Update Rollup 1 for SP4, if they have not been installed already

RESOLUTION
HP strongly recommends the immediate installation of all security patches that apply to third party software which is integrated with SMA software products supplied by HP, and that patches are applied in accordance with an appropriate patch management policy.

[security bulletin] HPSBUX02351 SSRT080058 rev.5 - HP-UX Running BIND, Remote DNS Cache Poisoning

 Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf.

HP-UX Release / Action

B.11.23 running v9.2.0 /
 Install PHNE_37865; Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf.

HP-UX Release / Action

B.11.11 running v9.3.2 /
 Install revision C.9.3.2.7.0 or subsequent; Remove "query-source port" and "query-source-v6 port" options in

[security bulletin] HPSBUX02351 SSRT080058 rev.6 - HP-UX Running BIND, Remote DNS Cache Poisoning

B.11.11 running v9.2.0 / BIND920V15.depot / Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf.

HP-UX Release / Action

B.11.23 running v9.2.0 / Install PHNE_37865 or subsequent; Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf.

HP-UX Release / Action

B.11.11 running v9.3.2 / Install revision C.9.3.2.7.0 or subsequent; Remove "query-source port" and "query-source-v6 port" options in /etc/named.conf.


[security bulletin] HPSBMA02625 SSRT100138 rev.1 - HP OpenView Storage Data Protector, Remote Execution of Arbitrary Code

==================
DATA-PROTECTOR.OMNI-CORE-IS
DATA-PROTECTOR.OMNI-HPUX-P
DATA-PROTECTOR.OMNI-OTHUX-P
DATA-PROTECTOR.OMNI-NDMP-P
action: install PHSS_41363 or subsequent
DATA-PROTECTOR.OMNI-CS
action: install PHSS_41453 or subsequent
DATA-PROTECTOR.OMNI-CORE-IS
DATA-PROTECTOR.OMNI-HPUX-P
DATA-PROTECTOR.OMNI-OTHUX-P

[security bulletin] HPSBUX02435 SSRT090059 rev.1 - HP-UX Running OpenSSL, Remote Denial of Service (DoS), Bypass Security Restrictions

fips_1_1_2.FIPS-LIB 
fips_1_1_2.FIPS-MAN 
fips_1_1_2.FIPS-MIS 
fips_1_1_2.FIPS-RUN 
fips_1_1_2.FIPS-SRC 
action: install revision FIPS-OPENSSL-1.1.2.049 or subsequent 
fips_1_2.FIPS-CONF 
fips_1_2.FIPS-DOC 
fips_1_2.FIPS-INC 
fips_1_2.FIPS-LIB 
fips_1_2.FIPS-MAN 

[security bulletin] HPSBUX02418 SSRT090002 rev.1 - HP-UX Running OpenSSL, Remote Unauthorized Access

fips_1_1_2.FIPS-LIB 
fips_1_1_2.FIPS-MAN 
fips_1_1_2.FIPS-MIS 
fips_1_1_2.FIPS-RUN 
fips_1_1_2.FIPS-SRC 
action: install revision FIPS-OPENSSL-1.1.2.046 or subsequent 
fips_1_2.FIPS-CONF 
fips_1_2.FIPS-DOC 
fips_1_2.FIPS-INC 
fips_1_2.FIPS-LIB 
fips_1_2.FIPS-MAN 

[security bulletin] HPSBMA02331 SSRT080000 rev.3 - HP-UX running WBEM Services, Remote Execution of Arbitrary Code, Gain Extended Privileges

AFFECTED VERSIONS 

HP-UX B.11.11 
============= 
WBEMServices.WBEM-CORE 
action: install PHSS_38747 or subsequent 
http://itrc.hp.com 

HP-UX B.11.23 
============= 
WBEMServices.WBEM-CORE 

[security bulletin] HPSBST02360 SSRT080117 rev.2 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-041 to MS08-051

Note: The SMA must have all pertinent SMA Service Packs applied 

Windows 2000 Update Rollup 1

Customers are advised to download and install the Windows 2000 Update Rollup 1 for Service Pack 4 on SMA v2.1. For more information please refer to the Windows 2000 Update Rollup 1 for Service Pack 4 and Storage Management Appliance v2.1 advisory at the following website: http://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual&lang=en&cc=us&docIndexId=179111&taskId=101&prodTypeId=12169&prodSeriesId=315667 

Windows 2000 Update Rollup 1 for SP4 does not include security updates released after April 30, 2005 starting from MS05-026. It also does not include patches MS04-003 and MS04-028. Please install these patches in addition to Windows 2000 Update Rollup 1 for SP4, if they have not been installed already

RESOLUTION
HP strongly recommends the immediate installation of all security patches that apply to third party software which is integrated with SMA software products supplied by HP, and that patches are applied in accordance with an appropriate patch management policy.

VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.

      This update upgrades the service console rpms for bind-utils and
      bind-lib to version 9.2.4-22.el3.

      Version 9.2.4.-22.el3 addresses the recently discovered
      vulnerability in the BIND software used for Domain Name
      resolution (DNS). VMware doesn't install all the BIND packages
      on ESX Server and is not vulnerable by default to the reported
      vulnerability. Of the BIND packages, VMware only ships bind-util
      and bind-lib in the service console and these components by
      themselves cannot be used to setup a DNS server. Bind-lib and
      bind-util are used in client DNS applications like nsupdate,

[security bulletin] HPSBGN02298 SSRT071502 rev.3 - HP Notebook PC Quick Launch Button (QLB) Software Running on Windows, Remote Execution of Arbitrary Code, Gain Privileged Access

A potential security vulnerability has been identified with certain versions of the HP Notebook PC Quick Launch Button (QLB) software running on Windows. The vulnerability could be exploited remotely to execute arbitrary code or to gain privileged access.

References: CVE-2007-6331, CVE-2007-6332, CVE-2007-6333

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP Compaq business notebook PCs running the Microsoft Windows operating system with HP Quick Launch Button software v6.3 or earlier installed 

and

HP, HP Pavilion, and Compaq Presario consumer notebook PCs running the Microsoft Windows operating system with HP Quick Launch Button software v6.0 through v6.3 installed


[security bulletin] HPSBMA02239 SSRT061260 rev.3 - HP OpenView Operations (OVO) Agents Running Shared Trace Service, Remote Arbitrary Code Execution

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP OpenView OVO Agents OVO8.x HTTPS agents on AIX, HP-UX (IA and PA), HP Tru64 Unix, Solaris, and Windows running Shared Trace Service.

BACKGROUND

Note: HP OpenView Operations (OVO) requires HP OpenView Network Node Manager (OV NNM) on the OVO server. OVO will install OV NNM if it is not already present. OV NNM requires the installation of certain patches to be compatible with the resolution discussed below. To insure correct operation the recommendations of Security Bulletin HPSBMA02242 SSRT061260 must be implemented before the recommendations of this Security Bulletin. 

The Hewlett-Packard Company thanks Cody Pierce of TippingPoint DV Labs (dvlabs.tippingpoint.com) for reporting this vulnerability to security-alert@hp.com.

The Hewlett-Packard Company thanks an anonymous researcher working with the iDefense VCP for reporting this vulnerability to security-alert@hp.com. 


[security bulletin] HPSBST02299 SSRT071506 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-063 to MS07-069

NOTE: The SMA must have all pertinent SMA Service Packs applied

Windows 2000 Update Rollup 1

Customers are advised to download and install the Windows 2000 Update Rollup 1 for Service Pack 4 on SMA v2.1. For more information please refer to the Windows 2000 Update Rollup 1 for Service Pack 4 and Storage Management Appliance v2.1 advisory at the following website: http://h20000.www2.hp.com/bizsupport/TechSupport/DocumentIndex.jsp?contentType=SupportManual&lang=en&cc=us&docIndexId=179111&taskId=101&prodTypeId=12169&prodSeriesId=315667 

Windows 2000 Update Rollup 1 for SP4 does not include security updates released after April 30, 2005 starting from MS05-026. It also does not include patches MS04-003 and MS04-028. Please install these patches in addition to Windows 2000 Update Rollup 1 for SP4, if they have not been installed already

RESOLUTION
HP strongly recommends the immediate installation of all security patches that apply to third party software which is integrated with SMA software products supplied by HP, and that patches are applied in accordance with an appropriate patch management policy.

[security bulletin] HPSBUX02251 SSRT071449 rev.3 - HP-UX Running BIND, Remote DNS Cache Poisoning

For BIND v9.2.0 

HP-UX B.11.11 
============= 
BINDv920.INETSVCS-BIND 
action: install BIND920_v10.depot 

HP-UX B.11.23 
============= 
InternetSrvcs.INETSVCS2-RUN 
action: install PHNE_36973 or subsequent 

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!