Operating System - HP-UX
1834463 Members
2304 Online
110067 Solutions
New Discussion

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

 
SOLVED
Go to solution
Brando Sumayao
Advisor

CDE rpc.cmsd server remotely exploitable buffer overflow

Got scanned for network security/vulnerability and I was informed that my server had a "CDE rpc.cmsd server remotely exploitable buffer overflow". What does this mean and how do I fix it?

Thanks.
3 REPLIES 3
Sanjay_6
Honored Contributor

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Brando Sumayao
Advisor

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Sanjay,

I am running V11.11 and the link you referred me to mentions a patch as a fix but only for the ff:

For HP-UX release 11.00 PHSS_19483.

Could not find a patch for this vulnerability for V11.11.

Any thoughts?
Sanjay_6
Honored Contributor
Solution

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Hi Brando,

Seems like the patch PHSS_19483 has been supeceded by patch PHSS_25138. On going through the patch equivalency table it seems this problem was fixed in HP-UX 11.11. There is a possibility the problem was fixed in a later release of 11i than the one you are having on your system. Here is a thread on the patch equivalency table,

http://us-support.external.hp.com/wpsl/bin/doc.pl/screen=wpslEqTable/sid=a2a5c479027a441344?docid=equiv_data1100

If you are having this problem on 11i, look for CDE patches on 11i and hope those will solve your problems.

Hope this helps.

Regds