|
Brought to you by:
Suppliers of:
|
|
|
| |
A potential security vulnerability has been identified in HP-UX running the useradd(1M) command. The vulnerability could be exploited locally to allow unauthorized access to directories or files.
The incorrect use of certain useradd(1M) options can result in corruption of the /etc/default/useradd template file. The corrupt /etc/default/useradd template file can cause accounts to be created with incorrect ownership and permissions. The patches insure that useradd(1M) options are processed correctly in all cases. |
| |
Credit:
The information has been provided by Hewlett-Packard Company, HP Software Security Response Team.
The original article can be found at: https://www.hp.com/go/swa
|
| |
Vulnerable Systems:
* HP-UX B.11.11 - OS-Core.SYS-ADMIN action: install PHCO_38492 or subsequent, verify group id and home directory for all accounts URL: http://itrc.hp.com
* HP-UX B.11.23 - OS-Core.SYS-ADMIN OS-Core.SYS2-ADMIN action: install PHCO_38491 or subsequent, verify group id and home directory for all accounts URL: http://itrc.hp.com
* HP-UX B.11.31 - OS-Core.SYS2-ADMIN action: install PHCO_38547 or subsequent, verify group id and home directory for all accounts URL: http://itrc.hp.com
Patch Availability:
HP has made the following patches available to resolve this vulnerability. The patches are available from http://itrc.hp.com
HP-UX Release Patch ID
* B.11.11 (11i v1) PHCO_38492 or subsequent
* B.11.23 (11i v2) PHCO_38491 or subsequent
* B.11.31 (11i v3) PHCO_38547 or subsequent
CVE Information:
CVE-2009-0719
|
|
|
|
|