HP Ignite-UX Server Bug Lets Remote Users Obtain Root Access
|
|
SecurityTracker Alert ID: 1016942
|
|
SecurityTracker URL: http://securitytracker.com/id?1016942
|
|
CVE Reference: CVE-2006-5151
(Links to External Site)
|
Updated: Jun 3 2008
|
Original Entry Date: Sep 28 2006
|
Impact: Root access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: HP Security Bulletin
|
Version(s): prior to C.6.9.150
|
Description: A vulnerability was reported in HP Ignite-UX server. A remote user can obtain root privileges on the target system.
The vulnerability may be due to a "configuration issue." No further details were provided.
|
Impact: A remote user can gain root privileges on the target system.
|
Solution: HP has issued the following fixes, available at:
http://www.hp.com/go/softwaredepot
Ignite-UX-11-00_C.6.9.150_HP-UX_B.11.00_32+64.depot
Ignite-UX-11-11_C.6.9.150_HP
-UX_B.11.00_32+64.depot
Ignite-UX-11-23_C.6.9.150_HP-UX_B.11.00_32+64.depot
or
Ignite-UX_All_C.6.9.150.depot (contains all three
depots)
The HP advisory is available at:
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00778900
|
Vendor URL: www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00778900 (Links to External Site)
|
Cause: Configuration error
|
Underlying OS: UNIX (HP/UX)
|
Underlying OS Comments: B.11.00, B.11.11, B.11.23 running Ignite-UX server.
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 28 Sep 2006 07:28:50 -0400
Subject: HPSBUX02157 SSRT061220 rev.1 HP-UX Running Ignite-UX Server, Remote Unauthorized Access and Privilege Elevation
|
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00778900
|
|