HP-UX Running OpenSSL Unauthorized Data Injection and Denial of Service
17 Dec. 2009
Summary
A potential security vulnerability has been identified with HP-UX OpenSSL. The vulnerability could be exploited remotely to inject unauthorized data or to create a Denial of Service (DoS).
Vulnerable Systems:
* HP-UX B.11.11, B.11.23, B.11.31 running OpenSSL before version A.00.09.08l
Patch Availability:
B.11.11 PA (32 and 64) A.00.09.08l.001
B.11.23 (PA and IA) A.00.09.08l.002
B.11.31 (PA and IA) A.00.09.08l.003
Note: OpenSSL vA.00.09.08l disables renegotiation. Although renegotiation is thought to be rarely used, applications should be tested to evaluate the impact of installing OpenSSL vA.00.09.08l.
-------------------------------------------------------------------------------------------------------------------------------
This vulnerability and over 10,000 others are identified and reported by AVDS, the most technically sophisticated network vulnerability assessment and management system available.
*