HP-UX PHSS_35434 : HP-UX Running dtmail, Local Execution of Arbitrary Code (HPSBUX02162 SSRT061223 rev.1)

medium Nessus Plugin ID 22919

Synopsis

The remote HP-UX host is missing a security-related patch.

Description

s700_800 11.11 CDE Applications Patch :

A potential security vulnerability has been identified with HP-UX running dtmail. The vulnerability could be exploited by a local, authorized user to execute arbitrary code as a member of the 'mail' group. References: NETRAGARD-20060810.

Solution

Install patch PHSS_35434 or subsequent.

See Also

http://www.nessus.org/u?f511d9dd

Plugin Details

Severity: Medium

ID: 22919

File Name: hpux_PHSS_35434.nasl

Version: 1.13

Type: local

Published: 10/25/2006

Updated: 1/11/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:hp:hp-ux

Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist

Patch Publication Date: 10/18/2006

Vulnerability Publication Date: 10/20/2006

Reference Information

CVE: CVE-2006-5452

HP: HPSBUX02162, SSRT061223, emr_na-c00793091