Secunia Logo
 
HP Tru64 NFS AdvFS Memory Corruption
Secunia Advisory: SA9780
Release Date: 2003-09-18
Popularity: 7,671 views

Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch

OS:HP Tru64 UNIX 5.x

Subscribe: Instant alerts on relevant vulnerabilities


Description:
A vulnerability has been identified in HP Tru64 NFS when handling files on AdvFS possibly allowing malicious users to cause a Denial of Service.

The problem has been reported to occur under certain circumstances when certain non Tru64 NFS clients try to increase the size of a file on a AdvFS. This could result in a kernel memory fault or corruption kernel memory.

Solution:
ECO kits are available:

ECO Name: T64KIT0019921-V51AB21-E-20030909
Kit Applies To: HP Tru64 UNIX 5.1A PK4 (BL21)
http://ftp.support.compaq.com/patches.../t64kit0019921-v51ab21-e-20030909.tar

ECO Name: T64KIT0019920-V51BB22-E-20030909
Kit Applies To: HP Tru64 UNIX 5.1B PK2 (BL22)
http://ftp.support.compaq.com/patches.../t64kit0019920-v51bb22-e-20030909.tar

ECO Name: T64KIT0019900-V51AB23-E-20030906
Kit Applies To: HP Tru64 UNIX 5.1A PK5 (BL23)
http://ftp.support.compaq.com/patches.../t64kit0019900-v51ab23-e-20030906.tar

Original Advisory:
http://ftp.support.compaq.com/patches...4kit0019921-v51ab21-e-20030909.README
http://ftp.support.compaq.com/patches...4kit0019920-v51bb22-e-20030909.README
http://ftp.support.compaq.com/patches...4kit0019900-v51ab23-e-20030906.README


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 152 views
2. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 84 views
3. VLC Media Player Real Demuxer Integer Overflow Vulnerability // 81 views
4. VMware ESX / ESXi Virtual Hardware Memory Corruption Vulnerability // 59 views
5. VMware ESX Server update for bzip2 // 47 views
6. SquirrelMail Malformed HTML Mail Message Script Insertion // 43 views
7. Mozilla Firefox 3 Multiple Vulnerabilities // 36 views
8. mvnForum Unspecified Cross-Site Scripting and Request Forgery // 36 views
9. Movable Type Unspecified Cross-Site Scripting Vulnerability // 36 views
10. Sunbyte e-Flower "id" SQL Injection Vulnerability // 36 views