Operating System - HP-UX
1754328 Members
2941 Online
108813 Solutions
New Discussion юеВ

CDE rpc.cmsd server remotely exploitable buffer overflow

 
SOLVED
Go to solution
Steve Bear_1
Frequent Advisor

CDE rpc.cmsd server remotely exploitable buffer overflow

Recent sercurity scan on hpux 11.11 servers detected following Vulnerability

-----
CDE rpc.cmsd server remotely exploitable buffer overflow (CVE-1999-0696)

For HP-UX 10.20 and 11.00:

Apply the appropriate patch for your system, as listed in Hewlett-Packard Security Bulletin HPSBUX9908-102. See References.
--------

My question is the above reference is only for 10.20 and 11.00 and i couldnt find relevant patches for hpux 11.11

Where can i find above security patch for hpux 11.11 ?

Any suggestion ?
3 REPLIES 3
Pete Randall
Outstanding Contributor

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Steve,

The Security Bulletin says

"PLATFORM: HP-9000 Series 700/800 HP-UX releases 10.2X, 10.30, 11.00."

I believe the specific exclusion of 11.11 indicates that the fix has been incorporated in the release and the problem does not exist in 11.11.


Pete

Pete
Pete Randall
Outstanding Contributor
Solution

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

Steve,

To further that thought, that defect was reported in 1999, 11i was released in June of 2000. If we look at the recommended patch for 11.0 (PHSS_19483 - 1999/08/09), we see that the recommended patch is PHSS_30010 - 2003/11/10. If we look at PHSS_30010, we find that it still mentions the PHSS_19483 fix, but if we look at the equivalent 11i patch (PHSS_30011), there is no mention of the PHSS_19483 fix.

This also leads me to believe that the fix was already rolled into the code.


Pete

Pete
Steve Bear_1
Frequent Advisor

Re: CDE rpc.cmsd server remotely exploitable buffer overflow

you right Pete, even the patch equivalency table says PHSS_19483 has been fixed in 11.11.

I'll write back to security guys and find out the reason why they have reported this for 11.11.

Thanks,