OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA13025] HP-UX Apache Multiple Vulnerabilities

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri Oct 29 2004 - 06:05:36 CDT


TITLE:
HP-UX Apache Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA13025

VERIFY ADVISORY:
http://secunia.com/advisories/13025/

CRITICAL:
Moderately critical

IMPACT:
Security Bypass, Privilege escalation, DoS, System access

WHERE:
From remote

OPERATING SYSTEM:
HP-UX 11.x
http://secunia.com/product/138/

DESCRIPTION:
HP has confirmed some vulnerabilities in HP-UX Apache, which can be
exploited to cause a DoS (Denial of Service), bypass configured
access controls, gain escalated privileges, or potentially compromise
a vulnerable system.

For more information:
SA12434
SA12527
SA12540
SA12633

The vulnerabilities affect HP-UX B.11.00, B.11.11, B.11.22, and
B.11.23 running the HP-UX Apache-based web server.

SOLUTION:
HP-UX B.11.00, HP-UX B.11.11, and HP-UX B.11.23:
Install revision A.2.0.52.00 or subsequent.

HP-UX B.11.22:
Migrate to HP-UX B.11.23 and install revision A.2.0.52.00 or
subsequent.

ORIGINAL ADVISORY:
SSRT4853:
http://www4.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX01090

OTHER REFERENCES:
SA12434:
http://secunia.com/advisories/12434/

SA12527:
http://secunia.com/advisories/12527/

SA12540:
http://secunia.com/advisories/12540/

SA12633:
http://secunia.com/advisories/12633/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------