Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
|
|
|
|
|
|
|
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
|
|
|
|
Become a Partner and License Our Database or Notification Service
|
|
|
|
|
|
|
|
|
|
|
|
|
|
HP Select Identity Lets Local Users Access Other Accounts
|
|
SecurityTracker Alert ID: 1019746
|
|
SecurityTracker URL: http://securitytracker.com/id?1019746
|
|
CVE Reference: CVE-2008-0709
(Links to External Site)
|
Date: Apr 1 2008
|
Impact: User access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: HP Security Bulletin
|
Version(s): 4.00, 4.01, 4.11, 4.12, 4.13, 4.20
|
Description: A vulnerability was reported in HP Select Identity. A local user can obtain elevated privileges on the target system.
A local user can gain access to other accounts on the target system.
|
Impact: A local user can gain access to other accounts.
|
Solution: HP has issued the following fixes.
v4.00, Windows 2003 Server, and Red Hat Linux AS3:
HPSI patch 4.00.013
v4.01, HP-UX,
Windows 2003 Server, Red Hat Linux AS3, and Solaris:
HPSI patch 4.01.015
v4.11, HP-UX, Windows 2003 Server, and Red Hat Linux
AS3:
HPSI patch 4.11.001HF2
v4.12, HP-UX, Windows 2003 Server, Red Hat Linux AS3, and Solaris:
HPSI patch 4.12.000HF7
v4.13,
HP-UX, Windows 2003 Server, Red Hat Linux AS3, and Solaris:
HPSI patch 4.13.005
v4.20, HP-UX, Windows 2003 Server, and Red
Hat Linux AS4:
HPSI patch 4.20.001HF1
The HP advisory is available at:
https://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01391833
|
Vendor URL: www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01391833 (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Red Hat Enterprise), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 1 Apr 2008 17:16:12 -0500
Subject: HPSBMA02317 SSRT080026 rev.1 - HP Select Identity Software, Gain Unauthorized Access
|
https://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01391833
CVE-2008-0709
|
|
Go to the Top of This SecurityTracker Archive Page
|