OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA10774] HP TCP/IP Services for OpenVMS BIND Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Tue Feb 03 2004 - 07:05:09 CST


TITLE:
HP TCP/IP Services for OpenVMS BIND Vulnerability

SECUNIA ADVISORY ID:
SA10774

VERIFY ADVISORY:
http://www.secunia.com/advisories/10774/

CRITICAL:
Not critical

IMPACT:
DoS

WHERE:
From local network

SOFTWARE:
HP TCP/IP Services for OpenVMS 5.x

DESCRIPTION:
HP has acknowledged that TCP/IP for OpenVMS BIND 8 software is
affected by a vulnerability, which allows malicious people to poison
the DNS cache.

For more information:
SA10300

The vulnerability affects the following products:
* HP TCP/IP V5.1 for HP OpenVMS Alpha and VAX
* HP TCP/IP V5.3 for HP OpenVMS VAX

SOLUTION:
HP has issued temporary fixes until ECO kits are released.

Temporary fixes are available at:
ftp://vmstcpip:vmstcpiphprc.external.hp.com/

TCPIP$BIND_SERVER.EXE_ECO_I_V_V51
TCPIP$BIND_SERVER.EXE_ECO_I_A_V51
TCPIP$BIND_SERVER.EXE_ECO_G_V_V53

PROVIDED AND/OR DISCOVERED BY:
Reported by vendor.

OTHER REFERENCES:
SA10300:
http://www.secunia.com/advisories/10300/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://www.secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://www.secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------