home *** CD-ROM | disk | FTP | other *** search
- Date: Thu, 18 Mar 1999 12:36:13 -0800
- From: aleph1@UNDERGROUND.ORG
- Reply-To: support_feedback@us-support.external.hp.com
- To: BUGTRAQ@netspace.org
- Subject: Security Bulletins Digest
-
- HP Support Information Digests
-
- ===============================================================================
- o HP Electronic Support Center World Wide Web Service
- ---------------------------------------------------
-
- If you subscribed through the HP Electronic Support Center and would
- like to be REMOVED from this mailing list, access the
- HP Electronic Support Center on the World Wide Web at:
-
- http://us-support.external.hp.com
-
- Login using your HP Electronic Support Center User ID and Password.
- Then select Support Information Digests. You may then unsubscribe from the
- appropriate digest.
- ===============================================================================
-
- ?
- Digest Name: Daily Security Bulletins Digest
- Created: Thu Mar 18 3:00:02 PST 1999
-
- Table of Contents:
-
- Document ID Title
- --------------- -----------
- HPSBUX9903-093 Security Vulnerability with hpterm on HP-UX 10.20
-
- The documents are listed below.
- -------------------------------------------------------------------------------
-
- ?
- Document ID: HPSBUX9903-093
- Date Loaded: 19990317
- Title: Security Vulnerability with hpterm on HP-UX 10.20
-
- -------------------------------------------------------------------------
- HEWLETT-PACKARD COMPANY SECURITY BULLETIN: #00093, 18 March 1999
- -------------------------------------------------------------------------
-
- The information in the following Security Bulletin should be acted upon
- as soon as possible. Hewlett-Packard Company will not be liable for any
- consequences to any customer resulting from customer's failure to fully
- implement instructions in this Security Bulletin as soon as possible.
-
- -------------------------------------------------------------------------
- PROBLEM: PHSS_13560 introduced a library access problem into hpterm.
-
- PLATFORM: HP9000 Series 700 and Series 800, HP-UX release 10.20 only.
-
- DAMAGE: Users can gain increased privileges.
-
- SOLUTION: Install PHSS_17830.
-
- AVAILABILITY: The patch is available now.
-
- -------------------------------------------------------------------------
- I.
- A. Background
-
- PHSS_13560 introduced a library access problem into hpterm, the
- terminal emulator for the X Window system. (See hpterm(1)).
-
- B. Fixing the problem
-
- Installing patch PHSS_17830 completely fixes this problem.
-
- NOTE: Three older hpterm patches have been released including
- PHSS_13560, PHSS_15431, and PHSS_17332. All of these older
- patches are being superseded with the release of the
- PHSS_17830.
-
- Do not use PHSS_13560, PHSS_15431, or PHSS_17332.
-
-
- C. To subscribe to automatically receive future NEW HP Security
- Bulletins from the HP Electronic Support Center via electronic
- mail, do the following:
-
- Use your browser to get to the HP Electronic Support Center page
- at:
-
- http://us-support.external.hp.com
- (for US, Canada, Asia-Pacific, & Latin-America)
- http://europe-support.external.hp.com (for Europe)
-
- Login with your user ID and password (or register for one).
- Remember to save the User ID assigned to you, and your password.
- Once you are in the Main Menu:
- To -subscribe- to future HP Security Bulletins,
- click on "Support Information Digests".
- To -review- bulletins already released from the main Menu,
- click on the "Technical Knowledge Database (Security Bulletins
- only)".
- Near the bottom of the next page, click on "Browse the HP Security
- Bulletin Archive".
-
- Once in the archive there is another link to our current Security
- Patch Matrix. Updated daily, this matrix categorizes security
- patches by platform/OS release, and by bulletin topic.
-
- The security patch matrix is also available via anonymous ftp:
-
- us-ffs.external.hp.com
- ~ftp/export/patches/hp-ux_patch_matrix
-
- D. To report new security vulnerabilities, send email to
-
- security-alert@hp.com
-
- Please encrypt any exploit information using the security-alert
- PGP key, available from your local key server, or by sending a
- message with a -subject- (not body) of 'get key' (no quotes) to
- security-alert@hp.com.
-
- Permission is granted for copying and circulating this Bulletin to
- Hewlett-Packard (HP) customers (or the Internet community) for the
- purpose of alerting them to problems, if and only if, the Bulletin
- is not edited or changed in any way, is attributed to HP, and
- provided such reproduction and/or distribution is performed for
- non-commercial purposes.
-
- Any other use of this information is prohibited. HP is not liable
- for any misuse of this information by any third party.
- _______________________________________________________________________
- -----End of Document ID: HPSBUX9903-093--------------------------------------
-
-