HP Data Protector Express Lets Local Users Gain Elevated Privileges and Deny Service
|
|
SecurityTracker Alert ID: 1022220 |
|
SecurityTracker URL: http://securitytracker.com/id/1022220
|
|
CVE Reference:
CVE-2009-0714
(Links to External Site)
|
Updated: Sep 3 2010
|
Original Entry Date: May 14 2009
|
Impact:
Denial of service via local system, Execution of arbitrary code via local system, User access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 3.5 SP2, 4.0 SP1; and prior service packs
|
Description:
A vulnerability was reported in HP Data Protector Express and HP Data Protector Express Single Server Edition. A local user can obtain elevated privileges on the target system. A local user can cause denial of service conditions.
A local user can execute arbitrary code on the target system.
A local user can affect the availability of the target system.
|
Impact:
A local user can obtain elevated privileges on the target system.
A local user can cause denial of service conditions on the target system.
|
Solution:
The vendor has issued a fix (HotFix Build 56936 for 3.5 SP2, HotFix Build 56906 for 4.0 SP1).
The vendor's advisory is available at:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543
|
Vendor URL: h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543 (Links to External Site)
|
Cause:
Not specified
|
Underlying OS:
Linux (Red Hat Enterprise), Linux (SuSE), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 14 May 2009 00:08:40 -0400
Subject: HPSBMA02417 SSRT090031 rev.1 - HP Data Protector Express and HP Data Protector Express Single Server Edition (SSE), Local Denial of Service (DoS), Execution of Arbitrary Code
|
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543
CVE-2009-0714
|
|