xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

HP MPE/iX畸形SNMP漏洞


发布时间:2002-06-21
更新时间:2002-06-21
严重程度:
威胁程度:远程管理员权限
错误类型:意外情况处置错误
利用方式:服务器模式

BUGTRAQ ID:5043

受影响系统
HP MPE/iX 4.0
HP MPE/iX 4.5
HP MPE/iX 5.0
HP MPE/iX 5.5
HP MPE/iX 6.0
HP MPE/iX 6.5
HP MPE/iX 7.0
详细描述
MPE/iX是HP E3000级别服务器上的INTERNET相关操作系统。

MPE/iX存在漏洞允许远程攻击者通过利用SNMP协议攻击。

SNMP协议实现存在漏洞,请检查以前的漏洞描述。

测试代码


解决方案
补丁下载:

HP MPE/iX 4.0:
HP MPE/iX 4.5:
HP MPE/iX 5.0:
HP MPE/iX 5.5:
HP MPE/iX 6.0:

HP Patch SNMGDL9A
http://itrc.hp.com
This patch is dependant on the following patches: NMSGDF2A or later NMS patch (NMSGDF2A is GR) NMCGDF3A or later NMC patch (NMCGDM4A is GR)

HP MPE/iX 6.5:

HP Patch SNMGDM0A
http://itrc.hp.com
This patch is dependant on the following patches: NMSGDD3A or later NMS patch (NMSGDD3A is GR) NMCGDD2A or later NMC patch (NMCGDM5A is GR)

HP MPE/iX 7.0:

HP Patch SNMGDM1A
http://itrc.hp.com
This patch is dependant on the following patches: NMSGDD6A or later NMS patch (NMSGDD6A is GR) NMCGDD5A or later NMC patch (NMCGDD5A is GR)

相关信息
Oulu University Secure Programming Group
参考:http://online.securityfocus.com/bid/4088
http://online.securityfocus.com/bid/4089