HPSBGN02234 SSRT071435 rev.1 - HP ServiceGuard for Linux, Local Unauthorized Access, Increase in Privilege

  • KM02992247
  • 17-Oct-2017
  • 17-Oct-2017

Summary

A potential security vulnerability has been identified with HP Serviceguard for Linux. The vulnerability could be exploited to allow local unauthorized access or to increase privilege.

Reference

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: KM02992247 (c01091941)

Version: 1

HPSBGN02234 SSRT071435 rev.1 - HP ServiceGuard for Linux, Local Unauthorized Access, Increase in Privilege
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

Release Date: 2007-06-26

Last Updated: 2007-07-01


Potential Security Impact: Local unauthorized access, increase in privilege

Source: Hewlett Packard Enterprise, HPE Product Security Response Team

VULNERABILITY SUMMARY

A potential security vulnerability has been identified with HP Serviceguard for Linux. The vulnerability could be exploited to allow local unauthorized access or to increase privilege.

References: None

SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.

HP Serviceguard for Linux: 
RedHatAS2.1/ES2.1 releases SG A.11.14.04, A.11.14.05, A.11.14.06 
Serviceguard Cluster Object Manager B.02.01.02, B.02.01.03 

RedHat3.0AS RedHat3.0ES releases SG A.11.16.04, A.11.16.05, A.11.16.06, A.11.16.07, A.11.16.08, A.11.16.09, A.11.16.10 
Serviceguard Cluster Object Manager B.03.01.02 
 

BACKGROUND

This vulnerability does not affect the SUSE versions of HP Serviceguard and Cluster Object Manager.

RESOLUTION

HP has provided the following software patches to resolve this vulnerability. 
The patches are available for download from: http://itrc.hp.com 
Retrieve applicable patches and install using applicable Linux tools. 

RedHat Enterprise Linux, release Serviceguard A.11.16.11 
RedHat3.0AS RedHat3.0ES
IA32
SGLX_00150
RedHat3.0AS RedHat3.0ES
IA64
SGLX_00151
RedHat3.0AS RedHat3.0ES
x86_64
SGLX_00152


RedHat4AS RedHat4ES
IA32
SGLX_00121
RedHat4AS RedHat4ES
IA64
SGLX_00122
RedHat4AS RedHat4ES
x86_64
SGLX_00123


RedHat Enterprise Linux, release Cluster Object Manager B.03.01.03 

RedHat3.0AS RedHat3.0ES
IA32
SGLX_00153
RedHat3.0AS RedHat3.0ES
IA64
SGLX_00154
RedHat3.0AS RedHat3.0ES
x86_64
SGLX_00155


RedHat4AS RedHat4ES
IA32
SGLX_00130
RedHat4AS RedHat4ES
IA64
SGLX_00131
RedHat4AS RedHat4ES
x86_64
SGLX_00132


RedHat Enterprise Linux, release Serviceguard A.11.14.07 
RedHatAS 2.1, RedHatES 2.1
IA32
SGLX_00148


RedHat Enterprise Linux, release Cluster Object Manager B.02.01.04 
RedHatAS 2.1, RedHatES 2.1
IA32
SGLX_00149


PRODUCT SPECIFIC INFORMATION 

None 

HISTORY 
Version: 1 (rev.1) - 2 July 2007 Initial release 

Third Party Security Patches: Third party security patches which are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.
©Copyright 2017 Hewlett Packard Enterprise Company, L.P.
Hewlett Packard Enterprise Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HPE nor its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett Packard Enterprise Company and the names of Hewlett Packard Enterprise Company products referenced herein are trademarks of Hewlett Packard Enterprise Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners.