HP-UX Running VRTSweb Remote Execution of Arbitrary Code and Privilege Escalation
10 Dec. 2009
Summary
A potential security vulnerability has been identified with HP-UX running VRTSweb version 5.0. The vulnerability could be exploited remotely to execute arbitrary code or increase privilege.
Vulnerable Systems:
* HP-UX B.11.23 running VRTSweb prior to version 5.0
* HP-UX B.11.31 running VRTSweb prior to version 5.0
* HP-UX B.11.31 running VRTSweb prior to version 5.0.1
Patch Availability:
HP has provided the following patches to resolve this vulnerability. The patches are available from the following location: URL: http://itrc.hp.com
B.11.23 (IA and PA) VRTSweb prior to v5.0 PHCO_40518 or subsequent
B.11.31 VRTSweb prior to v5.0 PHCO_40519 or subsequent
B.11.31 VRTSweb prior to v5.0.1 PHCO_40520 or subsequent
-------------------------------------------------------------------------------------------------------------------------------
This vulnerability and over 10,000 others are identified and reported by AVDS, the most technically sophisticated network vulnerability assessment and management system available.
*