HP Security Bulletin HPSBUX02795 SSRT100878 - A potential security vulnerability has been identified with HP-UX running BIND. This vulnerability could be exploited remotely to create a Denial of Service (DoS). Revision 1 of this advisory.
2bc00a1d4f7b7a8ff1008f02f3b03cffcd18b4c8bbce60774e1e9b0a98a4ca2c
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Note: the current version of the following document is available here:
https://h20566.www2.hp.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c03388901
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c03388901
Version: 1
HPSBUX02795 SSRT100878 rev.1 - HP-UX Running BIND, Remote Denial of Service
(DoS)
NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible.
Release Date: 2012-07-02
Last Updated: 2012-06-29
Potential Security Impact: Remote Denial of Service (DoS)
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
A potential security vulnerability has been identified with HP-UX running
BIND. This vulnerability could be exploited remotely to create a Denial of
Service (DoS).
References: CVE-2012-1667
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
HP-UX B.11.31 running BIND 9.3 prior to C.9.3.2.12.0-beta
HP-UX B.11.11 and B.11.23 running BIND 9.3 prior to C.9.3.2.10.0-beta
BACKGROUND
CVSS 2.0 Base Metrics
===========================================================
Reference Base Vector Base Score
CVE-2012-1667 (AV:N/AC:L/Au:N/C:P/I:N/A:C) 8.5
===========================================================
Information on CVSS is documented
in HP Customer Notice: HPSN-2008-002
RESOLUTION
HP has provided patched versions of the BIND service to resolve this
vulnerability. When final depots are released this bulletin will be revised.
These upgrades are available from the following location
ftp://s02795:Secure12@ftp.usa.hp.com
BIND 9.3.2 for HP-UX Release
Depot Name
B.11.11 (PA and IA)
BIND93-1111-unof.depot
B.11.23 (PA and IA)
BIND93-1123-unof.depot
B.11.31 (PA and IA)
BIND93-1131-unof.depot
MANUAL ACTIONS: Yes - Update
Download and install the software update
PRODUCT SPECIFIC INFORMATION
HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application
that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins
issued by HP and lists recommended actions that may apply to a specific HP-UX
system. It can also download patches and create a depot automatically. For
more information see: https://www.hp.com/go/swa
The following text is for use by the HP-UX Software Assistant.
AFFECTED VERSIONS
For BIND 9.3
HP-UX B.11.11
==================
BindUpgrade.BIND-UPGRADE
action: install revision C.9.3.2.10.0-beta or subsequent
HP-UX B.11.23
==================
BindUpgrade.BIND-UPGRADE
BindUpgrade.BIND2-UPGRADE
action: install revision C.9.3.2.10.0-beta or subsequent
HP-UX B.11.31
==================
NameService.BIND-AUX
NameService.BIND-RUN
action: install revision C.9.3.2.12.0-beta or subsequent
END AFFECTED VERSIONS
HISTORY
Version:1 (rev.1) - 2 July 2012 Initial release
Support: For further information, contact normal HP Services support channel.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAk/x7UgACgkQ4B86/C0qfVnDKwCfdhUI/Fwj5/FvWUtBrCs6Piyv
O4sAnRxebX6v4e4QfMBIRBNX6viELFEk
=Rt9t
-----END PGP SIGNATURE-----