Vulnerable Systems:
* HP-UX B.11.31 running NFS / ONCplus version B.11.31_08 or previous
Immune Systems:
* N/A
A potential security vulnerability has been identified with NFS/ONCplus running on HP-UX. The vulnerability could result in the inadvertent enabling of NFS.
Installing ONCplus will result in having NFS_SERVER=1 in /etc/rc.config.d/nfsconf regardless of the original setting. This can result in inadvertently enabling NFS.
Patch Availability:
Install ONCplus_B.11.31.09.depot to preserve NFS_SERVER value when updating.
Check and correct NFS_SERVER and NFS_CLIENT values.