HP-UX PHCO_42178 : HP-UX running VEA, Remote Denial of Service (DoS), Execution of Arbitrary Code (HPSBUX02700 SSRT100506 rev.2)

This script is Copyright (C) 2012-2014 Tenable Network Security, Inc.


Synopsis :

The remote HP-UX host is missing a security-related patch.

Description :

s700_800 11.31 VRTS 5.0.1 VRTSob Command Patch :

Potential security vulnerabilities have been identified in HP-UX
running the Veritas Enterprise Administrator (VEA), which comes
bundled with VxVM. The vulnerabilities could be exploited remotely to
create a Denial of Service (DoS) or execute arbitrary code.
References: CVE-2011-0547, ZDI-CAN-1110, ZDI-CAN-1111.

See also :

http://www.nessus.org/u?a55dd2ee

Solution :

Install patch PHCO_42178 or subsequent.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: HP-UX Local Security Checks

Nessus Plugin ID: 56829 ()

Bugtraq ID: 47824
49014

CVE ID: CVE-2011-0547