|
|
| |
Credit:
The original article can be found at: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01961959
|
| |
Vulnerable Systems:
* HP TCP/IP Services for OpenVMS v5.5 on Itanium platforms.
* HP TCP/IP Services for OpenVMS v5.5 on Alpha platforms.
* HP TCP/IP Services for OpenVMS v5.6 on Itanium platforms.
* HP TCP/IP Services for OpenVMS v5.6 on Alpha platforms.
Potential security vulnerabilities have been identified with HP TCP/IP Services for OpenVMS Running NTP. The vulnerabilities could be remotely exploited to execute arbitrary code or create a Denial of Service.
Patch Availability:
NTP for HP OpenVMS TCPIP patch kits are available for both ALPHA and ITANIUM platforms.
HP has made the following patch kits available to resolve the vulnerability:
HP OpenVMS v 5.4 ECO 7 - Platform ALPHA - Patch: NTP_V54/ECO7/qxcr1000910870_v54_eco7_alpha.bck
HP OpenVMS v 5.5 ECO 3 - Platform ALPHA - Patch: NTP_V55/ECO3/QXCR1000910870_V55_ECO3_ALPHA.BCK
HP OpenVMS v 5.5 ECO 3 - Platform Itanium - Patch: NTP_V55/ECO3/QXCR1000910870_V55_ECO3_I64.BCK
HP OpenVMS v 5.6 ECO 4 - Platform ALPHA - Patch: NTP_V56/ECO4/qxcr1000910870_v56_eco4_alpha.bck
HP OpenVMS v 5.6 ECO 4 - Platform Itanium - Patch: NTP_V56/ECO4/qxcr1000910870_v56_eco4_i64.bck
HP OpenVMS v 5.6 ECO 5 - Platform ALPHA - Patch: NTP_V56/ECO5/QXCR1000910870_V56_ECO5_ALPHA.BCK
HP OpenVMS v 5.6 ECO 5 - Platform Itanium - Patch: NTP_V56/ECO5/QXCR1000910870_V56_ECO5_I64.BCK
CVE Information:
CVE-2009-0159
CVE-2009-1252
CVE-2009-3563
Disclosure Timeline:
2010-05-17: Release Date
2010-05-17: Last Updated
|
|
|