home *** CD-ROM | disk | FTP | other *** search
- Date: Tue, 13 Apr 1999 04:37:00 -0700 (PDT)
- Subject: Security Bulletins Digest
- >From: support_feedback@us-support.external.hp.com (HP Electronic Support Center )
- To: security_info@us-support.external.hp.com
- Reply-To: support_feedback@us-support.external.hp.com
- Errors-To: support_errors@us-support.external.hp.com
-
-
- HP Support Information Digests
-
- ===============================================================================
- o HP Electronic Support Center World Wide Web Service
- ---------------------------------------------------
-
- If you subscribed through the HP Electronic Support Center and would
- like to be REMOVED from this mailing list, access the
- HP Electronic Support Center on the World Wide Web at:
-
- http://us-support.external.hp.com
-
- Login using your HP Electronic Support Center User ID and Password.
- Then select Support Information Digests. You may then unsubscribe from the
- appropriate digest.
- ===============================================================================
-
- ?
- Digest Name: Daily Security Bulletins Digest
- Created: Tue Apr 13 3:00:02 PDT 1999
-
- Table of Contents:
-
- Document ID Title
- --------------- -----------
- HPSBMP9904-006 Security Vulnerability in MPEi/X debug
-
- The documents are listed below.
- -------------------------------------------------------------------------------
-
- ?
- Document ID: HPSBMP9904-006
- Date Loaded: 19990412
- Title: Security Vulnerability in MPEi/X debug
-
- -------------------------------------------------------------------------
- HEWLETT-PACKARD COMPANY SECURITY BULLETIN: (MPE/iX) #006, 13 April 1999
- -------------------------------------------------------------------------
-
- The information in the following Security Bulletin should be acted upon
- as soon as possible. Hewlett-Packard Company will not be liable for any
- consequences to any customer resulting from customer's failure to fully
- implement instructions in this Security Bulletin as soon as possible.
-
- -------------------------------------------------------------------------
-
- PROBLEM : Debug improperly handles commands.
-
- PLATFORM: All HP3000 systems running the MPE/iX 5.0 and MPE/iX 5.5
- release of the Operating System only.
-
- DAMAGE : Users can gain increased privileges.
-
- SOLUTION: Apply the appropriate patches to correct the problem:
-
- For MPE/iX 5.0: MPEKXM1A
- For MPE/iX 5.5: MPEKXM1B
-
- ---------------------------------------------------------------------
- I.
- A. Background
- Under certain conditions, improper use of the debug utility
- in MPE/iX Operating system can result in users gaining increased
- privileges.
-
- B. Fixing the problem
- Obtain the patch from the HP Electronic Support Center (ESC)
- by following the instructions below. Installing the following
- patch will completely close this vulnerability.
-
- For all HP3000 platforms running MPE/iX 5.0: MPEKXM1A
- For all HP3000 platforms running MPE/iX 5.5: MPEKXM1B
-
- NOTE: The problem does not exist with the release MPE/iX 6.0.
-
- C. To subscribe to automatically receive future NEW HP Security
- Bulletins or access the HP Electronic Support Center, use your
- browser to get to our ESC web page at:
-
- http://us-support.external.hp.com (for non-European locations),
- or http://europe-support.external.hp.com (for Europe)
-
- Login with your user ID and password (or register for one).
- Remember to save the User ID/password assigned to you.
-
- Once you are in the Main Menu:
- To -subscribe- to future HP Security Bulletins,
- click on "Support Information Digests".
- To -review Security bulletins already released-,
- click on the "Search Technical Knowledge Database."
- To -retrieve patches-, click on "Individual Patches" and select
- appropriate release and locate with the patch identifier (ID).
- To -browse the HP Security Bulletin Archive-, select the link at
- the bottom of the page once in the "Support Information Digests".
- To -view the Security Patch Matrix-, (updated daily) which
- categorizes security patches by platform/OS release, and by
- bulletin topic, go to the archive (above) and follow the links.
-
- The security patch matrix is also available via anonymous ftp:
- us-ffs.external.hp.com or ~ftp/export/patches/hp-ux_patch_matrix
-
- D. To report new security vulnerabilities, send email to
-
- security-alert@hp.com
-
- Please encrypt any exploit information using the security-alert
- PGP key, available from your local key server, or by sending a
- message with a -subject- (not body) of 'get key' (no quotes) to
- security-alert@hp.com.
-
- Permission is granted for copying and circulating this Bulletin to
- Hewlett-Packard (HP) customers (or the Internet community) for the
- purpose of alerting them to problems, if and only if, the Bulletin
- is not edited or changed in any way, is attributed to HP, and
- provided such reproduction and/or distribution is performed for
- non-commercial purposes.
-
- Any other use of this information is prohibited. HP is not liable
- for any misuse of this information by any third party.
- ________________________________________________________________________
- -----End of Document ID: HPSBMP9904-006--------------------------------------
-