Release date:
Updated on:
Affected Systems:
HP OpenVMS Alpha 8.4
HP OpenVMS 8.3-1H1 Itanium
HP OpenVMS 8.3-1H1
HP OpenVMS 8.3 Itanium
HP OpenVMS 8.2.Alpha
HP OpenVMS 7.3-2 Alpha
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56895
CVE (CAN) ID: CVE-2012-3276, CVE-2012-3277
HP OpenVMS is a VMS-based multi-task multi-processor operating system.
When HP OpenVMS runs the ACME_SERVER process, the LOGIN function and ACMELOGIN function have a denial of service vulnerability. Remote or local attackers can exploit this vulnerability to cause a denial of service.
<* Source: vendor
Link: http://securitytracker.com/id/1027861
What is https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay? DocId = emr_na-c03599086
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
HP
--
HP has released a Security Bulletin (HPSBOV02834) and corresponding patches for this:
HPSBOV02834: SSRT101055 rev.1-HP OpenVMS LOGIN or ACMELOGIN, Remote or Local Denial of Service (DoS)
Https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay? DocId = emr_na-c03599086
Patch download: http://hp.com/go/hpsc