|
|
| |
Credit:
The original article can be found at: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02288473
|
| |
Vulnerable Systems:
* HP-UX B.11.11 running rpc.ttdbserver
* HP-UX B.11.23 running rpc.ttdbserver
* HP-UX B.11.31 running rpc.ttdbserver
A potential security vulnerability has been identified with HP-UX running rpc.ttdbserver. The vulnerability could be exploited remotely to execute arbitrary code.
Workaround:
The vulnerability can be resolved by disabling rtp.ttdbserver. Note: The rpc.ttdbserver process is not needed for programs provided in the HP CDE product.
To Disable rpc.ttdbserver:
Edit /etc/inetd.conf and comment out the rpc.ttdbserver line as follows:
#rpc stream tcp swait root /usr/dt/bin/rpc.ttdbserver ...
Restart inetd:
/usr/sbin/inetd -c
Kill any instances of rpc.ttdbserver that might be running.
CVE Information:
CVE-2010-0083
Disclosure Timeline:
2010-07-13: Release Date
2010-07-13: Last Updated
|
|
|