Oval Definition:oval:org.mitre.oval:def:5670
Revision Date:2015-04-20Version:27
Title:HP-UX Running IPv6, Remote Denial of Service (DoS) and Unauthorized Access
Description:The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).
Family:unixClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2008-2476
Platform(s):HP-UX 11
Product(s):
Definition Synopsis
  • Criteria meets HP Security Bulletin HPSBUX02407
  • HP-UX B.11.23
  • AND filesets tests
  • OS-Core.SYS2-ADMIN is installed
  • OR Networking.NMS2-KRN is installed
  • OR Networking.NET-RUN-64 is installed
  • OR OS-Core.CORE2-KRN is installed
  • OR Networking.NET-PRG is installed
  • OR Networking.NET-RUN is installed
  • OR ProgSupport.C-INC is installed
  • OR Networking.NET2-KRN is installed
  • OR Networking.NET2-RUN is installed
  • AND NOT Patch PHNE_37897 is installed
  • OR Criteria meets HP Security Bulletin HPSBUX02407
  • HP-UX B.11.11
  • AND filesets tests
  • Networking.NMS2-KRN is installed
  • OR Networking.NET-RUN-64 is installed
  • OR OS-Core.CORE2-KRN is installed
  • OR Networking.NET-PRG is installed
  • OR Networking.NET-RUN is installed
  • OR ProgSupport.C-INC is installed
  • OR Networking.NET2-KRN is installed
  • OR OS-Core.SYS-ADMIN is installed
  • OR Networking.NET-KRN is installed
  • OR OS-Core.CORE-KRN is installed
  • AND NOT Patch PHNE_37898 is installed
  • OR Criteria meets HP Security Bulletin HPSBUX02407
  • HP-UX B.11.31
  • AND filesets tests
  • OS-Core.SYS2-ADMIN is installed
  • OR Networking.NMS2-KRN is installed
  • OR Networking.NET-RUN-64 is installed
  • OR OS-Core.CORE2-KRN is installed
  • OR Networking.NET-RUN is installed
  • OR ProgSupport.C-INC is installed
  • OR Networking.NET2-KRN is installed
  • OR Networking.NET2-RUN is installed
  • AND NOT Patch PHNE_38680 is installed
  • BACK