[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bugtraq
Subject:    [security bulletin] HPSBUX02724 SSRT100650 rev.3 - HP-UX Running System Administration Manager (SAM)
From:       security-alert () hp ! com
Date:       2012-01-30 23:58:56
Message-ID: 20120130235856.1C57C1FCA2 () security ! hp ! com
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c03089106
Version: 3

HPSBUX02724 SSRT100650 rev.3 - HP-UX Running System Administration Manager (SAM), \
Local Increase in Privilege

NOTICE: The information in this Security Bulletin should be acted upon as soon as \
possible.

Release Date: 2011-11-16
Last Updated: 2012-01-30

 -------------------------------------------------------------------------------

Source: Hewlett-Packard Company, HP Software Security Response Team

VULNERABILITY SUMMARY
A potential security vulnerability has been identified with HP-UX running SAM. This \
vulnerability could be locally exploited to create an increase in privilege.

References: CVE-2011-4159

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP-UX 11.11 running EMS prior to A.04.20.11.06
HP-UX 11.23 running EMS prior to A.04.20.23.07
HP-UX 11.31 running EMS prior to A.04.20.31.08

BACKGROUND

CVSS 2.0 Base Metrics
===========================================================
  Reference              Base Vector             Base Score
CVE-2011-4159    (AV:L/AC:L/Au:S/C:C/I:C/A:C)       6.8
===========================================================
             Information on CVSS is documented
            in HP Customer Notice: HPSN-2008-002

RESOLUTION

HP has provided unofficial upgrades to resolve this vulnerability.
The upgrades are available from the following location
https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=EventMonitoring


HP-UX Release
 A.04.20.X Depot Name

B.11.11 PA (32 and 64)
 EventMonitoring_A.04.20.11.06_HP-UX_B.11.11_32_64.depot

B.11.23 (PA and IA)
 EventMonitoring_A.04.20.23.07_HP-UX_B.11.23_IA_PA.depot

B.11.31 (PA and IA)
 EventMonitoring_A.04.20.31.08_HP-UX_B.11.31_IA_PA.depot

MANUAL ACTIONS: Yes - Update
Install A.04.20.X or subsequent

PRODUCT SPECIFIC INFORMATION
HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that \
replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP \
and lists recommended actions that may apply to a specific HP-UX system. It can also \
download patches and create a depot automatically. For more information see: \
https://www.hp.com/go/swa

The following text is for use by the HP-UX Software Assistant.

AFFECTED VERSIONS

HP-UX B.11.11
==================
EMS-Config.EMS-GUI
EMS-Core.EMS-CORE
EMS-Core.EMS-MX
EMS-Core.EMS-WRAPPER
EMS-MIBMonitor.MIBMON-RUN
action: install revision A.04.20.11.06 or subsequent

HP-UX B.11.23
==================
EMS-Config.EMS-GUI
EMS-Config.EMS-GUI-COM
EMS-Core.EMS-CORE
EMS-Core.EMS-CORE-COM
EMS-Core.EMS-MX
EMS-Core.EMS-WRAPPER
EMS-Core.EMS-WRAPPER-COM
EMS-MIBMon.MIBMON-RUN
EMS-MIBMon.MIBMON-RUN-COM
action: install revision A.04.20.23.07 or subsequent

HP-UX B.11.31
==================
EMS-Config.EMS-GUI
EMS-Config.EMS-GUI-COM
EMS-Core.EMS-CORE
EMS-Core.EMS-CORE-COM
EMS-Core.EMS-MX
EMS-Core.EMS-WRAPPER
EMS-Core.EMS-WRAPPER-COM
EMS-MIBMon.MIBMON-RUN
EMS-MIBMon.MIBMON-RUN-COM
action: install revision A.04.20.31.08 or subsequent

END AFFECTED VERSIONS

HISTORY
Version:1 (rev.1) 16 November 2011 Initial release
Version:2 (rev.2) 21 November 2011 New depots, revised supported software versions
Version:3 (rev.3) 30 January 2012 Final depots available

Third Party Security Patches: Third party security patches that are to be installed \
on systems running HP software products should be applied in accordance with the \
customer's patch management policy.

Support: For issues about implementing the recommendations of this Security Bulletin, \
contact normal HP Services support channel.  For other issues about the content of \
this Security Bulletin, send e-mail to security-alert@hp.com.

Report: To report a potential security vulnerability with any HP supported product, \
send Email to: security-alert@hp.com

Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts \
via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Security Bulletin List: A list of HP Security Bulletins, updated periodically, is \
contained in HP Security Notice HPSN-2011-001: \
https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c02964430


Security Bulletin Archive: A list of recently released Security Bulletins is \
available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/

Software Product Category: The Software Product Category is represented in the title \
by the two characters following HPSB.

3C = 3COM
3P = 3rd Party Software
GN = HP General Software
HF = HP Hardware and Firmware
MP = MPE/iX
MU = Multi-Platform Software
NS = NonStop Servers
OV = OpenVMS
PI = Printing and Imaging
PV = ProCurve
ST = Storage Software
TU = Tru64 UNIX
UX = HP-UX

Copyright 2012 Hewlett-Packard Development Company, L.P.
Hewlett-Packard Company shall not be liable for technical or editorial errors or \
omissions contained herein. The information provided is provided "as is" without \
warranty of any kind. To the extent permitted by law, neither HP or its affiliates, \
subcontractors or suppliers will be liable for incidental,special or consequential \
damages including downtime cost; lost profits;damages relating to the procurement of \
substitute products or services; or damages for loss of data, or software \
restoration. The information in this document is subject to change without notice. \
Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein \
are trademarks of Hewlett-Packard Company in the United States and other countries. \
Other product and company names mentioned herein may be trademarks of their \
                respective owners.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAk8nDfMACgkQ4B86/C0qfVkd7QCfeWGu8pJm+wrMBpeI1YS/S5tm
mUYAoOe3evNFdI4A8lIIYXfgRcZ0dTST
=U4CX
-----END PGP SIGNATURE-----


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic