Vissza a www.andrews.hu-ra

    [guru] HP biztonsagi frissitesek


    DATE: Thu, 05 Jun 2008 09:46:50 +0200
    Storage termékcsalád:
    ---------------------
    Stack buffer overflow hibát találtak a HP StorageWorks Storage Mirroring
    termékében. A hiba a DoubleTake.exe processz authentikáció kezelésében
    található, így a támadónak nem kell jogosultsággal rendelkeznie a rendszere.
    
    
    Egyéb:
    ------
    A HP Instant Support HPISDataManager.dll ActiveX vezérlője több súlyos
    biztonsági hibát is tartalmaz, amiknek segítségével a támadó kódot futtathat
    az áldozat rendszerén. A HP számítógépekre az ActiveX vezérlőt gyárilag
    installálják.
    
    
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    SUPPORT COMMUNICATION - SECURITY BULLETIN
    
    Document ID: c01362558
    Version: 1
    
    HPSBST02312 SSRT071428 rev.1 - HP StorageWorks Storage Mirroring Software, Remote Execution of Arbitrary Code
    
    NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.
    
    Release Date: 2008-06-02
    Last Updated: 2008-06-02
    
    Potential Security Impact: Remote execution of arbitrary code. 
    
    Source: Hewlett-Packard Company, HP Software Security Response Team
    
    VULNERABILITY SUMMARY
    A potential security vulnerability has been identified in HP StorageWorks Storage Mirroring (SWSM) software. This vulnerability could allow remote execution of arbitrary code. 
    
    References: CVE-2008-1661. 
    
    SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
    HP StorageWorks Storage Mirroring software v4.5 Service Pack 1. 
    
    BACKGROUND
    
    CVSS 2.0 Base Metrics 
    ===============================================
    Reference                         Base Vector               Base Score 
    CVE-2008-1661     (AV:N/AC:M/Au:N/C:C/I:C/A:C)      9.3
    ===============================================
    Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.
    CVSS 2.0 Base Metrics 
    
    
    The Hewlett-Packard Company thanks Titon of BastardLabs working with TippingPoint's Zero Day Initiative for reporting this vulnerability to security-alert@hp.com.
    
    RESOLUTION
    
    To resolve this vulnerability download HP StorageWorks Storage Mirroring software v4.5 Service Pack 2 (SP2) from Double-Take at the following URL: http://www.doubletake.com/products/double-take/default.aspx 
    
    Note: Double-Take v5.0 (HP StorageWorks Storage Mirroring software v5.0) is now available for download from the above URL; this version includes the resolution to the stated vulnerability as well as a broad range of new features and improvements. 
    
    
    PRODUCT SPECIFIC INFORMATION 
    None 
    
    HISTORY 
    Version:1 (rev.1) - 2 June 2008 Initial release 
    
    Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. 
    
    Support: For further information, contact normal HP Services support channel.
    
    Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com 
    It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. 
    To get the security-alert PGP key, please send an e-mail message as follows:
      To: security-alert@hp.com 
      Subject: get key
    
    Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email: 
    http://h30046.www3.hp.com/driverAlertProfile.php?regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driverITRC&topiccode=ITRC 
    On the web page: ITRC security bulletins and patch sign-up 
    Under Step1: your ITRC security bulletins and patches 
      - check ALL categories for which alerts are required and continue.
    Under Step2: your ITRC operating systems 
      - verify your operating system selections are checked and save.
    
    
    To update an existing subscription: http://h30046.www3.hp.com/subSignIn.php 
    Log in on the web page: Subscriber's choice for Business: sign-in. 
    On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections.
    
    
    To review previously published Security Bulletins visit: http://www.itrc.hp.com/service/cki/secBullArchive.do 
    
    
    * The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number in the title: 
    
    GN = HP General SW
    MA = HP Management Agents
    MI = Misc. 3rd Party SW
    MP = HP MPE/iX
    NS = HP NonStop Servers
    OV = HP OpenVMS
    PI = HP Printing & Imaging
    ST = HP Storage SW
    TL = HP Trusted Linux
    TU = HP Tru64 UNIX
    UX = HP-UX
    VV = HP VirtualVault
     
    System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.
    
    
    "HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
    
    ©Copyright 2008 Hewlett-Packard Development Company, L.P. 
    
    Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.
    -----BEGIN PGP SIGNATURE-----
    Version: PGP 8.1
    
    iQA/AwUBSEQ5zeAfOvwtKn1ZEQJh5QCeJ0jMp8gDcF3CSyalUVuRQPJA2OkAoP2V
    +RrdQ15BV3orpb7CYAdHIZyj
    =NwUD
    -----END PGP SIGNATURE-----
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    ZDI-08-034: HP StorageWorks Storage Mirroring Authentication Processing 
    Stack Overflow Vulnerability
    http://www.zerodayinitiative.com/advisories/ZDI-08-034
    June 4, 2008
    
    -- CVE ID:
    CVE-2008-1661
    
    -- Affected Vendors:
    Hewlett-Packard
    
    -- Affected Products:
    Hewlett-Packard StorageWorks
    
    -- TippingPoint(TM) IPS Customer Protection:
    TippingPoint IPS customers have been protected against this
    vulnerability by Digital Vaccine protection filter ID 6051. 
    For further product information on the TippingPoint IPS, visit:
    
        http://www.tippingpoint.com
    
    -- Vulnerability Details:
    This vulnerability allows remote attackers to execute arbitrary code on
    vulnerable installations of Hewlett Packard StorageWorks Storage
    Mirroring. Authentication is not required to exploit this
    vulnerability.
    
    The specific flaw exists in the DoubleTake.exe process bound by default
    on TCP ports 1100, 1106 and UDP port 1105. During the handling of an
    encoded authentication request, the process copies the user-supplied
    login information into a fixed length stack buffer. Sending at least 256
    bytes will trigger a stack based buffer overflow due to a vulnerable
    processing loop. Exploitation of this issue can result in arbitrary code
    execution.
    
    -- Vendor Response:
    Hewlett-Packard states:
    To resolve this vulnerability download HP StorageWorks Storage Mirroring
    software v4.5 Service Pack 2 (SP2) from Double-Take at the following
    URL: http://www.doubletake.com/products/double-take/default.aspx
    
    -- Disclosure Timeline:
    2007-05-22 - Vulnerability reported to vendor
    2008-06-04 - Coordinated public release of advisory
    
    -- Credit:
    This vulnerability was discovered by:
        * Titon of BastardLabs
    
    -- About the Zero Day Initiative (ZDI):
    Established by TippingPoint, The Zero Day Initiative (ZDI) represents 
    a best-of-breed model for rewarding security researchers for responsibly
    disclosing discovered vulnerabilities.
    
    Researchers interested in getting paid for their security research
    through the ZDI can find more information and sign-up at:
    
        http://www.zerodayinitiative.com
    
    The ZDI is unique in how the acquired vulnerability information is
    used. TippingPoint does not re-sell the vulnerability details or any
    exploit code. Instead, upon notifying the affected product vendor,
    TippingPoint provides its customers with zero day protection through
    its intrusion prevention technology. Explicit details regarding the
    specifics of the vulnerability are not exposed to any parties until
    an official vendor patch is publicly available. Furthermore, with the
    altruistic aim of helping to secure a broader user base, TippingPoint
    provides this vulnerability information confidentially to security
    vendors (including competitors) who have a vulnerability protection or
    mitigation product.
    
    Our vulnerability disclosure policy is available online at:
    
        http://www.zerodayinitiative.com/advisories/disclosure_policy/
    
    CONFIDENTIALITY NOTICE: This e-mail message, including any attachments,
    is being sent by 3Com for the sole use of the intended recipient(s) and
    may contain confidential, proprietary and/or privileged information.
    Any unauthorized review, use, disclosure and/or distribution by any 
    recipient is prohibited.  If you are not the intended recipient, please
    delete and/or destroy all copies of this message regardless of form and
    any included attachments and notify 3Com immediately by contacting the
    sender via reply e-mail or forwarding to 3Com at postmaster@3com.com. 
    

    --- End Message ---
    --- Begin Message ---
    Multiple buffer overflow vulnerabilities in HP Software
    
    
    
     
    
    
    
    Hewlett-Packard (HP) is the world's largest PC dealer. According to IDC, HP shipped 14.7 million units worldwide, a 23.3 percent year-over-year growth and a 19 percent market share. 
    
    
    
     
    
    
    
    PC's and laptops from HP are often shipped with preinstalled software running on Microsoft Windows. The software is designed so the end-user can keep drivers and HP software automatically updated. This is done through a ActiveX plugin for Microsoft Internet Explorer.
    
    
    
     
    
    
    
    CSIS have discovered multiple high-risk vulnerabilities in several parts of that specific software. The affected component are found preinstalled on a broad range of HP equipment but are also installed when a end user visits HP webpage in order to access software updates such as applications, drivers and firmware for multiple HP products.
    
    
    
     
    
    
    
    We have discovered eight different vulnerabilities of which five should be considered highly critical since they allow remote code execution.
    
    
    
     
    
    
    
    At least five of these vulnerabilities have been confirmed to work in a typical drive-by scenario. All it takes to exploit is to lure a user into visiting a hostile and specifically crafted website. The attack could also be done through SQL and HTML injection. This would allow, if the system is found vulnerable, to run arbitrary code and take complete control of the system or at least with the privileges of the logged on user. In order for this scenario to work it would only require one of the affected ActiveX objects to be installed and Active scripting to be enabled in Microsoft Internet Explorer, which it is by default.
    
    
    
     
    
    
    
    The vulnerability was discovered and reported by Dennis Rand from CSIS Security Group.
    
    
    
     
    
    
    
    HP has released an advisory and update to address these vulnerabilities. 
    
    
    
    HP Instant Support HPISDataManager.dll Running on Windows, Remote Execution of Arbitrary Code
    
    
    
    http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01422264
    
    
    
     
    
    
    
    Technical advisory with PoC can be downloaded here:
    
    
    
    http://www.csis.dk/dk/forside/CSIS-RI-0003.pdf
    
    
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    SUPPORT COMMUNICATION - SECURITY BULLETIN
    
    Document ID: c01422264
    Version: 1
    
    HPSBMA02326 SSRT071490 rev.1 - HP Instant Support HPISDataManager.dll Running on Windows, Remote Execution of Arbitrary Code
    
    NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.
    
    Release Date: 2008-06-03
    Last Updated: 2008-06-03
    
    Potential Security Impact: Remote execution of arbitrary code
    
    Source: Hewlett-Packard Company, HP Software Security Response Team
    
    VULNERABILITY SUMMARY
    Potential security vulnerabilities have been identified with ActiveX controls in HP Instant Support HPISDataManager.dll running on Microsoft Windows. The vulnerabilities could be remotely exploited to allow remote execution of arbitrary code. 
    
    References: CVE-2007-5604 (CERT VU#754403), CVE-2007-5605 (CERT VU#558163), CVE-2007-5606 (CERT VU#221123), CVE-2007-5607 (CERT VU#526131), CVE-2007-5608 (CERT VU#949587), CVE-2007-5610 (CERT VU#857539), CVE-2008-0952 (CERT VU#190939), CVE-2008-0953 (CERT VU#998779)
    
    SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
    HP Instant Support HPISDataManager.dll v1.0.0.22 and earlier.
    
    BACKGROUND
    
    CVSS 2.0 Base Metrics 
    ===============================================
    Reference                         Base Vector               Base Score 
    CVE-2007-5604     (AV:N/AC:M/Au:N/C:C/I:C/A:C)     9.3
    CVE-2007-5605     (AV:N/AC:M/Au:N/C:C/I:C/A:C)     9.3
    CVE-2007-5606     (AV:N/AC:M/Au:N/C:C/I:C/A:C)     9.3
    CVE-2007-5607     (AV:N/AC:M/Au:N/C:C/I:C/A:C)     9.3
    CVE-2007-5608     (AV:N/AC:M/Au:N/C:N/I:P/A:N)     4.3
    CVE-2007-5610     (AV:N/AC:M/Au:N/C:N/I:N/A:P)     4.3
    CVE-2008-0952     (AV:N/AC:L/Au:N/C:N/I:C/A:N)     7.8
    CVE-2008-0953     (AV:N/AC:M/Au:N/C:C/I:C/A:P)     9
    ===============================================
    Information on CVSS is documented in HP Customer Notice: HPSN-2008-002.
    
    The Hewlett-Packard Company thanks Dennis Rand of CSIS Security Research and Intelligence for reporting this vulnerability to security-alert@hp.com.
    
    RESOLUTION
    
    Note: The vulnerabilities exist whether HP Instant Support is in use or not. The vulnerabilities must be addressed by one of the methods described below. 
    
    HP has provided the following software update to HP Instant Support resolve these vulnerabilities:
    
    ===============================================
    HP Instant Support - v1.0.0.24 or later
    ===============================================
    
    To install HP Instant Support - v1.0.0.24 or later, choose to ?launch an online diagnostic session? from the Instant Support Professional edition web site: http://www.hp.com/go/ispe 
    
    The vulnerabilities can also be resolved by the following procedure:
    
    Set the kill bit for the vulnerable ActiveX control's Class identifier (CLSID) {14C1B87C-3342-445F-9B5E-365FF330A3AC} . The kill bit is set by modifying the data value of the Compatibility Flags DWORD value for the CLSID of this ActiveX control to 0x00000400. This is explained in Microsoft's article KB240797 or subsequent. http://support.microsoft.com/kb/240797 
    
    PRODUCT SPECIFIC INFORMATION 
    None 
    
    History: 
    Version: 1 (rev.1) - 3 June 2008 Initial release 
    
    Support: For further information, contact normal HP Services support channel.
    
    Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com 
    It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. 
    To get the security-alert PGP key, please send an e-mail message as follows:
      To: security-alert@hp.com 
      Subject: get key
    
    Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email: 
    http://h30046.www3.hp.com/driverAlertProfile.php?regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driverITRC&topiccode=ITRC 
    On the web page: ITRC security bulletins and patch sign-up 
    Under Step1: your ITRC security bulletins and patches 
      - check ALL categories for which alerts are required and continue.
    Under Step2: your ITRC operating systems 
      - verify your operating system selections are checked and save.
    
    
    To update an existing subscription: http://h30046.www3.hp.com/subSignIn.php 
    Log in on the web page: Subscriber's choice for Business: sign-in. 
    On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections.
    
    
    To review previously published Security Bulletins visit: http://www.itrc.hp.com/service/cki/secBullArchive.do 
    
    
    * The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number in the title: 
    
    GN = HP General SW
    MA = HP Management Agents
    MI = Misc. 3rd Party SW
    MP = HP MPE/iX
    NS = HP NonStop Servers
    OV = HP OpenVMS
    PI = HP Printing & Imaging
    ST = HP Storage SW
    TL = HP Trusted Linux
    TU = HP Tru64 UNIX
    UX = HP-UX
    VV = HP VirtualVault
    
    System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions.
    
    
    "HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
    
    ©Copyright 2008 Hewlett-Packard Development Company, L.P. 
    
    Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.
    -----BEGIN PGP SIGNATURE-----
    Version: PGP 8.1
    
    iQA/AwUBSEWHsOAfOvwtKn1ZEQKbjACfSv6lqPGT3oC1RQB9jwQnMxQcwNkAoNsL
    iJxtro9j6XIH1NAShkAJ0vIi
    =+f1m
    -----END PGP SIGNATURE-----
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra