HP-UX PHSS_35434 : HP-UX Running dtmail, Local Execution of Arbitrary Code (HPSBUX02162 SSRT061223 rev.1)

Medium Nessus Plugin ID 22919


The remote HP-UX host is missing a security-related patch.


s700_800 11.11 CDE Applications Patch :

A potential security vulnerability has been identified with HP-UX running dtmail. The vulnerability could be exploited by a local, authorized user to execute arbitrary code as a member of the 'mail' group. References: NETRAGARD-20060810.


Install patch PHSS_35434 or subsequent.

See Also


Plugin Details

Severity: Medium

ID: 22919

File Name: hpux_PHSS_35434.nasl

Version: $Revision: 1.11 $

Type: local

Published: 2006/10/25

Modified: 2014/03/12

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:hp:hp-ux

Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist

Patch Publication Date: 2006/10/18

Vulnerability Publication Date: 2006/10/20

Reference Information

CVE: CVE-2006-5452

OSVDB: 29974

HP: emr_na-c00793091, HPSBUX02162, SSRT061223