Operating System - HP-UX
1834431 Members
2113 Online
110067 Solutions
New Discussion

CDE rpc.cmsd server remotely exploitable buffer overflow

 
SOLVED
Go to solution
Brando Sumayao
Advisor

CDE rpc.cmsd server remotely exploitable buffer overflow

Got scanned for network security/vulnerability and I was informed that my server had a "CDE rpc.cmsd server remotely exploitable buffer overflow". What does this mean and how do I fix it?

Thanks.
3 REPLIES 3
Sanjay_6
Honored Contributor

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Brando Sumayao
Advisor

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Sanjay,

I am running V11.11 and the link you referred me to mentions a patch as a fix but only for the ff:

For HP-UX release 11.00 PHSS_19483.

Could not find a patch for this vulnerability for V11.11.

Any thoughts?
Sanjay_6
Honored Contributor
Solution

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Hi Brando,

Seems like the patch PHSS_19483 has been supeceded by patch PHSS_25138. On going through the patch equivalency table it seems this problem was fixed in HP-UX 11.11. There is a possibility the problem was fixed in a later release of 11i than the one you are having on your system. Here is a thread on the patch equivalency table,

http://us-support.external.hp.com/wpsl/bin/doc.pl/screen=wpslEqTable/sid=a2a5c479027a441344?docid=equiv_data1100

If you are having this problem on 11i, look for CDE patches on 11i and hope those will solve your problems.

Hope this helps.

Regds