HP-UX PHSS_28090 : HP-UX Running Apache, Increased Privileges or Denial of Service (DoS) or Execution of Arbitrary Code (HPSBUX00224 SSRT2393 rev.3)
High Nessus Plugin ID 17118
SynopsisThe remote HP-UX host is missing a security-related patch.
Descriptions700_800 11.04 Virtualvault 4.6 IWS update. :
Potential vulnerability regarding ownership permissions of System V shared memory based scoreboards. (CERT VU#825353, CVE CAN-2002-0839) Potential cross-site scripting vulnerability in the default error page when using wildcard DNS. (CERT VU#240329, CVE CAN-2002-0840) Potential overflows in ab.c which could be exploited by a malicious server.
(CERT VU#858881, CVE CAN-2002-0843) Exposure of CGI source when a POST request is sent to a location where both DAV and CGI are enabled.
(CERT VU#91071, CVE CAN-2002-1156).
SolutionInstall patch PHSS_28090 or subsequent.