Operating System - HP-UX
1855308 Members
3125 Online
104109 Solutions
New Discussion

HPSBUX0306-266 SSRT3487 Potential Security Vulnerability in tftpd

 
Berlene Herren
Honored Contributor

HPSBUX0306-266 SSRT3487 Potential Security Vulnerability in tftpd

=================================================================
A security bulletin has been issued:

-----------------------------------------------------------------
Source: HEWLETT-PACKARD COMPANY
SECURITY BULLETIN: HPSBUX0306-266
Originally issued: 18 June 2003
SSRT3487 Potential Security Vulnerability in tftpd

-----------------------------------------------------------------

To access the bulletin from the itrc:

Select "maintenance and support"
Select "search technical knowledge base"
Select "HP-UX Software Security Bulletins"
Select "Search by Security Bulletin Number"
Enter "HPSBUX0306-266"
Search

The complete list of security bulletins can be found here:

http://itrc.hp.com/cki/bin/doc.pl/screen=ckiSecurityBulletin
=================================================================

Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
3 REPLIES 3
Dave Reichek
New Member

Re: HPSBUX0306-266 SSRT3487 Potential Security Vulnerability in tftpd

I follow your instructions, and the search produces no results.
Where in the HECK can I download the patch from?

Thanks
Berlene Herren
Honored Contributor

Re: HPSBUX0306-266 SSRT3487 Potential Security Vulnerability in tftpd

**REVISED 03**
Source: HEWLETT-PACKARD COMPANY
SECURITY BULLETIN: HPSBUX0306-266
Originally issued: 18 June 2003
Last revised: 10 June 2004
SSRT3487 rev.3 remote denial of service in tftpd
-----------------------------------------------------------------

NOTICE: There are no restrictions for distribution of this
Bulletin provided that it remains complete and intact.

The information in the following Security Bulletin should be
acted upon as soon as possible. Hewlett-Packard Company will
not be liable for any consequences to any customer resulting
from customer's failure to fully implement instructions in this
Security Bulletin as soon as possible.

-----------------------------------------------------------------
PROBLEM: Potential Security Vulnerability in tftpd.

IMPACT: Potential denial of service, remotely exploitable.

PLATFORM: HP-UX B.11.00,
--> HP-UX B.11.04, HP-UX B.11.11, HP-UX B.11.22

SOLUTION: B.11.00 - Install [PHNE_28828/PACHRDME/English] or subsequent.
B.11.04 - Install [PHNE_30589/PACHRDME/English] or subsequent.
--> B.11.11 - Install a preliminary patch as
described below.
B.11.22 - Install a preliminary patch as
described below.

MANUAL ACTIONS: Yes - NonUpdate
B.11.22 - Install a preliminary patch.
--> B.11.11 - Install a preliminary patch.
B.11.00, B.11.04 - No manual actions.

AVAILABILITY: The B.11.00 and B.11.04 patches are
available now on itrc.hp.com.

CHANGE SUMMARY: Rev.1 - added 11.00 patch.
Modified Section C with instructions for
Subscriber's Choice and other changes.
Rev.2 - added B.11.04 and B.11.11 patches.
Rev.3 - restored B.11.11 preliminary patch.
-----------------------------------------------------------------
A. Background

Certain network traffic can potentially cause tftpd to
become unresponsive resulting in a denial of service.

**REVISED 03**
-->Note: The B.11.11 patch mentioned in revision 2 of this
--> bulletin is not yet available for general release.
--> The B.11.11 preliminary patch, PHNE_29081.depot,
--> should continue to be used.


AFFECTED VERSIONS

Note: To determine if a system has an affected version,
search the output of "swlist -a revision -l fileset"
for an affected fileset. Then determine if the
recommended patch or update is installed.


HP-UX B.11.00
=============
InternetSrvcs.INETSVCS-BOOT
InternetSrvcs.INET-ENG-A-MAN
InternetSrvcs.INETSVCS-INC
action: Install [PHNE_28828/PACHRDME/English] or subsequent.

HP-UX B.11.04
=============
InternetSrvcs.INETSVCS-BOOT
InternetSrvcs.INET-ENG-A-MAN
InternetSrvcs.INETSVCS-INC
action: Install [PHNE_30589/PACHRDME/English] or subsequent.

**REVISED 03**
HP-UX B.11.11
=============
InternetSrvcs.INETSVCS-BOOT
--> action: Install PHNE_29081.depot.

HP-UX B.11.22
=============
InternetSrvcs.INETSVCS2-BOOT
action: Install PHNE_29130.depot

END AFFECTED VERSIONS

B. Recommended solution

HP-UX B.11.00 - Install [PHNE_28828/PACHRDME/English] or subsequent.
HP-UX B.11.04 - Install [PHNE_30589/PACHRDME/English] or subsequent.

-->HP-UX B.11.11 and HP-UX B.11.22:

1. Download the appropriate preliminary patch from the
following ftp site:

System: hprc.external.hp.com (192.170.19.51)
Login: tftpd
Password: tftpd

FTP Access: ftp://tftpd:tftpd@hprc.external.hp.com/
or: ftp://tftpd:tftpd@192.170.19.51/
or: ftp hprc.external.hp.com

B.11.11 - PHNE_29081.text
PHNE_29081.depot
B.11.22 - PHNE_29130.text
PHNE_29130.depot

Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
Steven E. Protter
Exalted Contributor

Re: HPSBUX0306-266 SSRT3487 Potential Security Vulnerability in tftpd

ewww.

This is a bad one.

OT: Any idea what happened to that sendmail beta?

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com