Ovom nadogradnjom ispravljene su višestruke sigurnosne ranjivosti paketa openssl koje su zlonamjernim korisnicima omogućavale zaobilaženje ograničenja, izvršavanje napada uskraćivanjem usluge te kompromitiranje ranjivog sustava.
Paket:
OpenSSL 1.x
Operacijski sustavi:
HP-UX 11.x
Kritičnost:
5.5
Problem:
pogreška u programskoj funkciji, pogreška u programskoj komponenti
Iskorištavanje:
lokalno/udaljeno
Posljedica:
neovlašteni pristup sustavu, uskraćivanje usluga (DoS), zaobilaženje postavljenih ograničenja
HP-UX update for OpenSSL
Secunia Advisory SA49229
Release Date 2012-05-18
Criticality level Highly criticalHighly critical
Impact Security Bypass
DoS
System access
Where From remote
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Vendor Patch
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia CSI, Secunia PSI
Automated scanning Secunia CSI, Secunia PSI
Operating System
HP-UX 11.x
Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2006-7250 CVSS available in Customer Area
CVE-2011-4619 CVSS available in Customer Area
CVE-2012-0884 CVSS available in Customer Area
CVE-2012-1165 CVSS available in Customer Area
CVE-2012-2110 CVSS available in Customer Area
CVE-2012-2131 CVSS available in Customer Area
Description
HP has issued an update for OpenSSL in HP-UX. This fixes multiple vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
For more information:
SA46958
SA47426
SA48153
SA48847
The vulnerabilities are reported in HP-UX versions B.11.11, B.11.23, and B.11.31 running OpenSSL versions prior to vA.00.09.08w.
Solution
Apply patches.
Further details available in Customer Area
Posljednje sigurnosne preporuke