int(998)

Vulnerability Bulletins


Denegación de Servicio en HP Systems Insight Manager

Vulnerability classification

Property Value
Confidence level Oficial
Impact Denegación de Servicio
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer UNIX
Affected software HP Systems Insight Manager 4.0 SP1 (Windows)
HP Systems Insight Manager 4.1 SP1 (Windows)
HP Systems Insight Manager 4.1 Update 1 (Linux)
HP Systems Insight Manager 4.01 (Linux)
HP-UX B.11.11 HP Systems Insight Manager 4.1 Update 1
HP-UX B.11.23 HP Systems Insight Manager 4.1 Update 1
HP-UX B.11.11 HP Systems Insight Manager 4.0 Update 1
HP-UX B.11.23 HP Systems Insight Manager 4.0 Update 1

Description

Microsoft ha publicado un parche para Internet Explorer( MS04-025 documentado en KB867801) que cambia el comportamiento de IE a la hora de tratar objetos binarios y scripts. Este cambio ha povocado que, al acceder a HP Systems Insight Manager parezca que el navegador se haya colapsado antes de pedir las credenciales.

Solution



Actualización de software

HP

Windows
HP Systems Insight Manager 4.0 SP1 - Instalar (SP26190)
HP Systems Insight Manager 4.1 SP1 - Instalar (SP26191)
http://h18013.www1.hp.com/products/servers/management/hpsim/index.html?jumpid=go/hpsim

HP-UX
HP Systems Insight Manager 4.1 Update 1 - Instalar HP-UX Critical Update Softpaq 26199
HP Systems Insight Manager 4.0 Update 1 - Instalar HP-UX Critical Update Softpaq 26198
http://h18013.www1.hp.com/products/servers/management/hpsim/index.html?jumpid=go/hpsim
HP Systems Insight Manager 4.2 Update 1
http://www.hp.com/go/hpsim

Linux
HP Systems Insight Manager 4.1 Update 1 - Linux
HP Systems Insight Manager 4.01 Update 1 - Linux
http://h18013.www1.hp.com/products/servers/management/hpsim/index.html?jumpid=go/hpsim

Standar resources

Property Value
CVE CVE-2005-3983
BID

Other resources

HP Security Advisory HPSBMA01072
http://www5.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01072

HP Security Advisory HPSBMA01075
http://www5.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01075

HP Security Advisory HPSBMA01076
http://www5.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMA01076

Version history

Version Comments Date
1.0 Aviso emitido 2004-09-03
1.1 Nuevos avisos emitidos por HP (HPSBMA01075 y HPSBMA01076) 2004-09-13
1.2 Aviso actualizado por HP (HPSBMA01076) 2005-11-30
Ministerio de Defensa
CNI
CCN
CCN-CERT