U radu programskog paketa HP OpenView Network Node Manager (OV NNM) uočena su tri sigurnosna nedostatka. Udaljenom napadaču omogućuju pokretanje proizvoljnog programskog koda.
Paket:
HP OpenView Network Node Manager 7.x
Operacijski sustavi:
HP-UX 11.x, Microsoft Windows 2000, Microsoft Windows XP, Sun Solaris 8, Sun Solaris 9
Kritičnost:
4.7
Problem:
nespecificirana pogreška
Iskorištavanje:
udaljeno
Posljedica:
proizvoljno izvršavanje programskog koda
Rješenje:
programska zakrpa proizvođača
CVE:
CVE-2011-3165, CVE-2011-3166, CVE-2011-3167
Izvorni ID preporuke:
HPSBMU02712
Izvor:
Hewlett Packard
Problem:
Nedostaci su posljedica zasad nespecificiranih pogrešaka.
Posljedica:
Napadač ih može iskoristiti za pokretanje proizvoljnog programskog koda.
Rješenje:
Svim se korisnicima savjetuje instalacija odgovarajućih zakrpa.
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c03054052
Version: 1
HPSBMU02712 SSRT100649 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.
Release Date: 2011-11-01
Last Updated: 2011-11-01
Potential Security Impact: Remote execution of arbitrary code
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). The vulnerabilities could be exploited remotely to execute arbitrary code under the context of the user running the web server.
References: CVE-2011-3165 (ZDI-CAN-1208), CVE-2011-3166 (ZDI-CAN-1209), CVE-2011-3167 (ZDI-CAN-1210)
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP OpenView Network Node Manager (OV NNM) v7.51, v7.53 running on HP-UX, Linux, Solaris, and Windows
BACKGROUND
For a PGP signed version of this security bulletin please write to: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
CVSS 2.0 Base Metrics
Reference
Base Vector
Base Score
CVE-2011-3165
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
6.4
CVE-2011-3166
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
6.4
CVE-2011-3167
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
6.4
Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.
The Hewlett-Packard Company thanks Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite. along with TippingPoint's Zero Day Initiative for reporting these vulnerabilities to Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite..
RESOLUTION
HP has made patches available to resolve the vulnerabilities for NNM v7.53.
OV NNM v7.53
The patches are available from http://support.openview.hp.com/selfsolve/patches
Operating System
Patch
HP-UX (IA)
PHSS_42233 or subsequent
HP-UX (PA)
PHSS_42232 or subsequent
Linux RedHatAS2.1
LXOV_00121 or subsequent
Linux RedHat4AS-x86_64
LXOV_00122 or subsequent
Solaris
PSOV_03535 or subsequent
Windows
NNM_01213 or subsequent
OV NNM v7.51
Upgrade to NNM v7.53 and apply the NNM v7.53 resolution listed above.
Patch bundles for upgrading from NNM v7.51 to NNM v7.53 are available using ftp:
Host
Account
Password
ftp.usa.hp.com
nnm_753
Update53
MANUAL ACTIONS: No
PRODUCT SPECIFIC INFORMATION
HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see https://www.hp.com/go/swa
The following text is for use by the HP-UX Software Assistant.
AFFECTED VERSIONS (for HP-UX)
For HP-UX OV NNM 7.51 and 7.53
HP-UX B.11.31
HP-UX B.11.23 (IA)
HP-UX B.11.23 (PA)
HP-UX B.11.11
=============
OVNNMgr.OVNNM-RUN,fr=B.07.50.00
action: install the patch listed in the Resolution
END AFFECTED VERSIONS (for HP-UX)
HISTORY
Version:1 (rev.1) - 1 November 2011 Initial release
Posljednje sigurnosne preporuke