HP TCP/IP Services for OpenVMS未授权访问安全漏洞


发布日期:2011-11-04
更新日期:2011-11-07

受影响系统:
HP TCP/IP Services for OpenVMS Alpha 5.7
HP TCP/IP Services for OpenVMS Alpha 5.6
HP TCP/IP Services for OpenVMS 5.7
HP TCP/IP Services for OpenVMS 5.6
描述:
--------------------------------------------------------------------------------
BUGTRAQ  ID: 50532
CVE ID: CVE-2011-3168

OpenVMS是基于VMS的多任务多处理器操作系统。

运行POP或IMAP服务器的HP TCP/IP Services for OpenVMS在实现上存在非法访问安全漏洞,远程攻击者可利用此漏洞绕过某些安全限制,并非法访问受影响应用程序。

<*来源:Peter Weaver
 
  链接:http://secunia.com/advisories/46743/
        http://h20566.www2.hp.com/
*>

建议:
--------------------------------------------------------------------------------
厂商补丁:

HP
--
HP已经为此发布了一个安全公告(HPSBOV0246)以及相应补丁:

HPSBOV0246:SSRT090152 rev.1 - HP TCP/IP Services for OpenVMS Running POP or IMAP, Remote Unauthorized Access

链接:http://h20566.www2.hp.com/

相关内容