Secunia Logo
Netsikker nu! 2008
 
HP Tru64 UNIX and HP Internet Express Sendmail Vulnerability
Secunia Advisory: SA20473
Release Date: 2006-06-07
Last Update: 2007-05-04
Popularity: 9,337 views

Critical:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status: Vendor Patch

OS:HP Tru64 UNIX 4.x
HP Tru64 UNIX 5.x

Software:HP Internet Express 6.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-0058
CVE-2006-1173


Description:
HP has acknowledged two vulnerabilities in HP Tru64 UNIX and HP Internet Express running sendmail, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.

For more information:
SA19342
SA15779

The vulnerabilities have been reported in the following versions:
* HP Tru64 UNIX 5.1B-3
* HP Tru64 UNIX 5.1B-2/PK4
* HP Tru64 UNIX 5.1A PK6
* HP Tru64 UNIX 4.0G PK4
* HP Tru64 UNIX 4.0F PK8
* HP Internet Express for Tru64 UNIX V6.3
* HP Internet Express for Tru64 UNIX V6.4
* HP Internet Express for Tru64 UNIX V6.5

Solution:
Apply ERP kits.

HP Tru64 UNIX Version 5.1B-3:
http://www2.itrc.hp.com/service/patch...hid=T64KIT1001125-V51BB26-ES-20070220
MD5 Checksum: bd43eb3b99466a9d82d01c1f5cc33f9c

HP Tru64 UNIX Version 5.1B-2/PK4:
http://www2.itrc.hp.com/service/patch...hid=T64KIT1000617-V51BB25-ES-20060515
MD5 Checksum: 1d8a0dc34628b5898c99b6dab2714320

HP Tru64 UNIX Version 5.1A PK6:
http://www2.itrc.hp.com/service/patch...hid=T64KIT1000618-V51AB24-ES-20060515
MD5 Checksum: b9a2ef1d0c1745ce0fa265b2d2fd8c32

HP Tru64 UNIX Version 4.0G PK4:
http://www2.itrc.hp.com/service/patch...hid=T64KIT1000635-V40GB22-ES-20060519
MD5 Checksum: 2c74941543d969c92adef38a44b5c764

HP Tru64 UNIX Version 4.0F PK8:
http://www2.itrc.hp.com/service/patch...hid=DUXKIT1000636-V40FB22-ES-20060519
MD5 Checksum: 9735ad5cc5c705e8bbbbefb01feb4128

HP Internet Express for Tru64 UNIX V6.3:
http://www2.itrc.hp.com/service/patch...=T64V51AB-IX-631-SENDMAIL-SSRT-061135
MD5 Checksum: ee9e7d5b0cc01e0424edc05021670820

HP Internet Express for Tru64 UNIX V6.4:
http://www2.itrc.hp.com/service/patch...=T64V51AB-IX-641-SENDMAIL-SSRT-061135
MD5 Checksum: 5b1a544575a62831c173fc489b8eaeea

HP Internet Explorer for Tru64 UNIX V6.5:
http://www2.itrc.hp.com/service/patch...=T64V51AB-IX-651-SENDMAIL-SSRT-061135
MD5 Checksum: 0b6268159a9957c56ff2f35cea2057d8

Changelog:
2006-06-15: Added information about additional vulnerability.
2007-05-04: Updated "Solution" section. The vendor has issued a new ERP kit for HP Tru64 UNIX v5.1B-3 because PSM functionality was broken in the HPSBTU02116 rev.2 ERP kit T64KIT1000619-V51BB26-ES-20060515.

Original Advisory:
HPSBTU02116 SSRT061135:
http://itrc.hp.com/service/cki/docDisplay.do?docId=c00692635

Other References:
SA19342:
http://secunia.com/advisories/19342/

SA15779:
http://secunia.com/advisories/15779/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB reveals user IPs // 100 views
2. phpBB Avatar Functions Information Disclosure and Deletion // 90 views
3. phpBB Avatar Script Insertion Vulnerability // 81 views
4. phpBB "url" bbcode Script Insertion Vulnerability // 45 views
5. phpBB Cross Site Scripting and Unspecified Vulnerabilities // 44 views
6. phpBB BBcode "url" Script Insertion Vulnerability // 42 views
7. phpBB "gen_rand_string()" Predictable RNG Weakness // 34 views
8. Zeroboard ".htaccess" File Upload Vulnerability // 32 views
9. CA ARCserve Backup Multiple Vulnerabilities // 29 views
10. ScriptsEz Easy Image Downloader "id" File Disclosure Vulnerability // 28 views