<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CDE rpc.cmsd server remotely exploitable buffer overflow in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338436#M190233</link>
    <description>Steve,&lt;BR /&gt;&lt;BR /&gt;To further that thought, that defect was reported in 1999, 11i was released in June of 2000.  If we look at the recommended patch for 11.0 (PHSS_19483 - 1999/08/09), we see that the recommended patch is PHSS_30010 - 2003/11/10.  If we look at PHSS_30010, we find that it still mentions the PHSS_19483 fix, but if we look at the equivalent 11i patch (PHSS_30011), there is no mention of the PHSS_19483 fix.&lt;BR /&gt;&lt;BR /&gt;This also leads me to believe that the fix was already rolled into the code.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
    <pubDate>Thu, 22 Jul 2004 05:51:11 GMT</pubDate>
    <dc:creator>Pete Randall</dc:creator>
    <dc:date>2004-07-22T05:51:11Z</dc:date>
    <item>
      <title>CDE rpc.cmsd server remotely exploitable buffer overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338434#M190231</link>
      <description>Recent sercurity scan on hpux 11.11 servers detected following Vulnerability&lt;BR /&gt;&lt;BR /&gt;-----&lt;BR /&gt;CDE rpc.cmsd server remotely exploitable buffer overflow (CVE-1999-0696)&lt;BR /&gt;&lt;BR /&gt;For HP-UX 10.20 and 11.00:&lt;BR /&gt;&lt;BR /&gt;Apply the appropriate patch for your system, as listed in Hewlett-Packard Security Bulletin HPSBUX9908-102. See References.&lt;BR /&gt;--------&lt;BR /&gt;&lt;BR /&gt;My question is the above reference is only for 10.20 and 11.00 and i couldnt find relevant patches for hpux 11.11 &lt;BR /&gt;&lt;BR /&gt;Where can i find above security patch for hpux 11.11 ? &lt;BR /&gt;&lt;BR /&gt;Any suggestion ?</description>
      <pubDate>Thu, 22 Jul 2004 05:29:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338434#M190231</guid>
      <dc:creator>Steve Bear_1</dc:creator>
      <dc:date>2004-07-22T05:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: CDE rpc.cmsd server remotely exploitable buffer overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338435#M190232</link>
      <description>Steve,&lt;BR /&gt;&lt;BR /&gt;The Security Bulletin says &lt;BR /&gt;&lt;BR /&gt;"PLATFORM: HP-9000 Series 700/800 HP-UX releases 10.2X, 10.30, 11.00."&lt;BR /&gt;&lt;BR /&gt;I believe the specific exclusion of 11.11 indicates that the fix has been incorporated in the release and the problem does not exist in 11.11.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Thu, 22 Jul 2004 05:39:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338435#M190232</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2004-07-22T05:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: CDE rpc.cmsd server remotely exploitable buffer overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338436#M190233</link>
      <description>Steve,&lt;BR /&gt;&lt;BR /&gt;To further that thought, that defect was reported in 1999, 11i was released in June of 2000.  If we look at the recommended patch for 11.0 (PHSS_19483 - 1999/08/09), we see that the recommended patch is PHSS_30010 - 2003/11/10.  If we look at PHSS_30010, we find that it still mentions the PHSS_19483 fix, but if we look at the equivalent 11i patch (PHSS_30011), there is no mention of the PHSS_19483 fix.&lt;BR /&gt;&lt;BR /&gt;This also leads me to believe that the fix was already rolled into the code.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Thu, 22 Jul 2004 05:51:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338436#M190233</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2004-07-22T05:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: CDE rpc.cmsd server remotely exploitable buffer overflow</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338437#M190234</link>
      <description>you right Pete, even the patch equivalency table says PHSS_19483 has been fixed in 11.11.&lt;BR /&gt;&lt;BR /&gt;I'll write back to security guys and find out the reason why they have reported this for 11.11.&lt;BR /&gt;&lt;BR /&gt;Thanks, &lt;BR /&gt;</description>
      <pubDate>Thu, 22 Jul 2004 06:11:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/cde-rpc-cmsd-server-remotely-exploitable-buffer-overflow/m-p/3338437#M190234</guid>
      <dc:creator>Steve Bear_1</dc:creator>
      <dc:date>2004-07-22T06:11:16Z</dc:date>
    </item>
  </channel>
</rss>

