HP-UX PHSS_36286 : HP-UX running Kerberos, Remote Arbitrary Code Execution (HPSBUX02217 SSRT071337 rev.2)

This script is Copyright (C) 2007-2014 Tenable Network Security, Inc.


Synopsis :

The remote HP-UX host is missing a security-related patch.

Description :

s700_800 11.11 KRB5-Client Version 1.0 cumulative patch :

A potential security vulnerability has been identified on HP-UX
running Kerberos. The vulnerability could be exploited by remote
authorized users to execute arbitrary code.

See also :

http://www.nessus.org/u?adb5d4c3

Solution :

Install patch PHSS_36286 or subsequent.

Risk factor :

High / CVSS Base Score : 8.5
(CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C)

Family: HP-UX Local Security Checks

Nessus Plugin ID: 26152 (hpux_PHSS_36286.nasl)

Bugtraq ID:

CVE ID: CVE-2007-1216