Oval Definition:
oval:org.mitre.oval:def:5958
Revision Date
:
2014-03-24
Version
:
19
Title
:
HP-UX running CDE, Local Increased Privilege, Denial of Service (DoS)
Description
:
Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.
Family
:
unix
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2001-0551
Platform(s)
:
HP-UX 11
Product(s)
:
Definition Synopsis
Criteria meets HP Security Bulletin HPSBUX00151
HP Release B.11.04
AND
filesets tests
CDE.CDE-ENG-A-HELP is installed
OR
CDE.CDE-FONTS is installed
OR
CDE.CDE-ENG-A-MSG is installed
OR
CDE-TT is installed
OR
CDE.CDE-MIN is installed
OR
CDE.CDE-RUN is installed
OR
CDE.CDE-SHLIBS is installed
OR
CDE.CDE-HELP-RUN is installed
OR
CDE.CDE-DTTERM is installed
OR
CDE.CDE-ENG-A-MAN is installed
AND
NOT
Patch PHSS_24098 is installed
OR
Criteria meets HP Security Bulletin HPSBUX00151
HP-UX B.11.11
AND
filesets tests
CDE.CDE-RUN is installed
OR
CDE.CDE-SHLIBS is installed
AND
Patch PHSS_24087 and PHSS_24091 are installed
Patch PHSS_24087 is installed
OR
Patch PHSS_24091 is installed
OR
Criteria meets HP Security Bulletin HPSBUX00151
HP Release B.11.00
AND
filesets tests
CDE.CDE-ENG-A-HELP is installed
OR
CDE.CDE-FONTS is installed
OR
CDE.CDE-ENG-A-MSG is installed
OR
CDE-TT is installed
OR
CDE.CDE-MIN is installed
OR
CDE.CDE-RUN is installed
OR
CDE.CDE-SHLIBS is installed
OR
CDE.CDE-HELP-RUN is installed
OR
CDE.CDE-DTTERM is installed
OR
CDE.CDE-ENG-A-MAN is installed
AND
NOT
Patch PHSS_23797 is installed
BACK