U radu programskog paketa HP BAC (Business Availability Center) uočeno je više sigurnosnih ranjivosti koje napadač može iskoristiti za zaobilaženje ograničenja, pokretanje proizvoljnih naredbi te DoS (eng. Denial of Service) napad.
Paket:
HP Business Availability Center 8.x
Operacijski sustavi:
HP-UX 11.x, Microsoft Windows XP, Microsoft Windows Server 2003, Microsoft Windows Vista, Microsoft Windows Server 2008, Microsoft Windows 7, Sun Solaris 7, Sun Solaris 8, Sun Solaris 9, Sun Solaris 10
Kritičnost:
7.5
Problem:
neodgovarajuće rukovanje pogreškama, pogreška u programskoj funkciji, pogreška u programskoj komponenti
Problemi sigurnosti su posljedica nepravilnog rukovanja pogreškama u funkciji "poll/unix/port.c", neodgovarajuće implementacije funkcije "ap_proxy_ftp_handler", greške u modulu "mod_proxy_ftp", itd.
Posljedica:
Udaljeni napadač navedene ranjivosti može iskoristiti za napad uskraćivanjem usluga (DoS), zaobilaženje ograničenja te pokretanje proizvoljnih naredbi.
Rješenje:
Svim se korisnicima navedenog programskog paketa savjetuje korištenje njegove najnovije inačice.
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c03236227
Version: 1
HPSBMU02753 SSRT100782 rev.1 - HP Business Availability Center (BAC) Running Apache, Remote Execution of Arbitrary Commands, Denial of Service (DoS)
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.
Release Date: 2012-04-02
Last Updated: 2012-04-02
Potential Security Impact: Remote execution of arbitrary commands, Denial of Service (DoS)
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with HP Business Availability Center (BAC) running Apache. The vulnerabilities could be remotely exploited to allow execution of arbitrary commands or to create a Denial of Service (DoS).
References: CVE-2009-2699, CVE-2009-3094, CVE-2009-3095, CVE-2010-1452
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
Business Availability Center (BAC) before v8.07 on Windows and Solaris
BACKGROUND
For a PGP signed version of this security bulletin please write to: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
CVSS 2.0 Base Metrics
Reference
Base vector
Base score
CVE-2009-2699
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
5.0
CVE-2009-3094
(AV:N/AC:H/Au:N/C:N/I:N/A:P)
2.6
CVE-2009-3095
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
7.5
CVE-2010-1452
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
5.0
Information on CVSS is documented in HP Customer Notice: HPSN-2008-002
RESOLUTION
HP has made Business Availability Center (BAC) v8.07 available to resolve the vulnerabilities.
BAC v8.07 supplies Apache 2.2.17.
HISTORY
Version:1 (rev.1) 2 April 2012 Initial release
Posljednje sigurnosne preporuke