Description: HP has acknowledged two vulnerabilities in HP Tru64 UNIX and HP Internet Express running sendmail, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
The vulnerabilities have been reported in the following versions:
* HP Tru64 UNIX 5.1B-3
* HP Tru64 UNIX 5.1B-2/PK4
* HP Tru64 UNIX 5.1A PK6
* HP Tru64 UNIX 4.0G PK4
* HP Tru64 UNIX 4.0F PK8
* HP Internet Express for Tru64 UNIX V6.3
* HP Internet Express for Tru64 UNIX V6.4
* HP Internet Express for Tru64 UNIX V6.5
Changelog: 2006-06-15: Added information about additional vulnerability.
2007-05-04: Updated "Solution" section. The vendor has issued a new ERP kit for HP Tru64 UNIX v5.1B-3 because PSM functionality was broken in the HPSBTU02116 rev.2 ERP kit T64KIT1000619-V51BB26-ES-20060515.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.