HP has provided the following web updates and patch to resolve the vulnerabilities.
The web updates and patch are available by contacting HP Support.
For Kerberos Web Update (KRB5CLIENT)
|
HP-UX Release
|
Depot name
|
|
B.11.11 (11i v1)
|
KRB5CLIENT_C.1.3.5.11_HP-UX_B.11.11_32_64.depot or subsequent
|
|
B.11.23 (11i v2)
|
KRB5CLIENT_D.1.6.2.09_HP-UX_B.11.23_IA_PA.depot or subsequent
|
|
B.11.31 (11i v3)
|
KRB5CLIENT_E.1.6.2.09_HP-UX_B.11.31_IA_PA.depot or subsequent
|
For Kerberos Client Product in Core-OS (KRB5-Client)
|
HP-UX Release
|
Patch ID
|
|
B.11.31 (11i v3)
|
PHSS_41775 or subsequent
|
NOTE:
HP-UX B.11.11 and B.11.23 Kerberos Client patches are based on MIT Kerberos version 1.0. That version is not impacted by these security vulnerabilities.
MANUAL ACTIONS:
Yes - NonUpdate
Upgrade to the versions listed under Resolution.
PRODUCT SPECIFIC INFORMATION
HP-UX Software Assistant:
HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see:
https://www.hp.com/go/swa
The following text is for use by the HP-UX Software Assistant.
AFFECTED VERSIONS
HP-UX B.11.11
==================
krb5client.KRB5-64SLIB-A
krb5client.KRB5-PRG-A
krb5client.KRB5-RUN-A
krb5client.KRB5-SHLIB-A
action: install revision C.1.3.5.11 or subsequent
HP-UX B.11.23
==================
krb5client.KRB5-64SLIB-A
krb5client.KRB5-PRG-A
krb5client.KRB5-RUN-A
krb5client.KRB5-SHLIB-A
krb5client.KRB5IA32SLIB-A
krb5client.KRB5IA64SLIB-A
action: install revision D.1.6.2.09 or subsequent
HP-UX B.11.31
==================
krb5client.KRB5-64SLIB-A
krb5client.KRB5-PRG-A
krb5client.KRB5-RUN-A
krb5client.KRB5-SHLIB-A
krb5client.KRB5IA32SLIB-A
krb5client.KRB5IA64SLIB-A
action: install revision E.1.6.2.09 or subsequent
HP-UX B.11.31
==================
KRB5-Client.KRB5-PRG
KRB5-Client.KRB5-64SLIB
KRB5-Client.KRB5-IA32SLIB
KRB5-Client.KRB5-IA64SLIB
KRB5-Client.KRB5-RUN
KRB5-Client.KRB5-SHLIB
action: install PHSS_41775 or subsequent
END AFFECTED VERSIONS
HISTORY
Version:1 (rev.1) 19 January 2011 Initial release
Third Party Security Patches:
Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy.