Vulnerabilities > CVE-2006-3097 - Local Denial of Service vulnerability in HP Hp-Ux 11.11/11.23

047910
CVSS 4.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
local
low complexity
hp
nessus

Summary

Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors. This vulnerability only affects HP-UX running Support Tools Manager (xstm, cstm, stm).

Vulnerable Configurations

Part Description Count
OS
Hp
2

Nessus

NASL familyHP-UX Local Security Checks
NASL idHPUX_PHSS_34288.NASL
descriptions700_800 11.11 Support Tool Manager September 2005 Patch : A potential security vulnerability has been identified with HP-UX running Support Tools Manager (xstm, cstm, stm). The vulnerability could be exploited by a local user to create a Denial of Service (DoS).
last seen2020-06-01
modified2020-06-02
plugin id21735
published2006-06-20
reporterThis script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/21735
titleHP-UX PHSS_34288 : HP-UX running Support Tools Manager (xstm, cstm, stm) Local Denial of Service (DoS) (HPSBUX02115 SSRT061077 rev.2)
code
#
# (C) Tenable Network Security, Inc.
#
# The descriptive text and patch checks in this plugin were 
# extracted from HP patch PHSS_34288. The text itself is
# copyright (C) Hewlett-Packard Development Company, L.P.
#

include("compat.inc");

if (description)
{
  script_id(21735);
  script_version("1.16");
  script_cvs_date("Date: 2019/07/10 16:04:13");

  script_cve_id("CVE-2006-3097");
  script_xref(name:"HP", value:"emr_na-c00657001");
  script_xref(name:"HP", value:"HPSBUX02115");
  script_xref(name:"HP", value:"SSRT061077");

  script_name(english:"HP-UX PHSS_34288 : HP-UX running Support Tools Manager (xstm, cstm, stm) Local Denial of Service (DoS) (HPSBUX02115 SSRT061077 rev.2)");
  script_summary(english:"Checks for the patch in the swlist output");

  script_set_attribute(
    attribute:"synopsis", 
    value:"The remote HP-UX host is missing a security-related patch."
  );
  script_set_attribute(
    attribute:"description", 
    value:
"s700_800 11.11 Support Tool Manager September 2005 Patch : 

A potential security vulnerability has been identified with HP-UX
running Support Tools Manager (xstm, cstm, stm). The vulnerability
could be exploited by a local user to create a Denial of Service
(DoS)."
  );
  # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00657001
  script_set_attribute(
    attribute:"see_also",
    value:"http://www.nessus.org/u?c3f77506"
  );
  script_set_attribute(
    attribute:"solution", 
    value:"Install patch PHSS_34288 or subsequent."
  );
  script_set_cvss_base_vector("CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C");

  script_set_attribute(attribute:"plugin_type", value:"local");
  script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux");

  script_set_attribute(attribute:"vuln_publication_date", value:"2006/06/20");
  script_set_attribute(attribute:"patch_publication_date", value:"2006/03/16");
  script_set_attribute(attribute:"plugin_publication_date", value:"2006/06/20");
  script_set_attribute(attribute:"patch_modification_date", value:"2012/06/26");
  script_set_attribute(attribute:"generated_plugin", value:"current");
  script_end_attributes();

  script_category(ACT_GATHER_INFO);
  script_copyright(english:"This script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.");
  script_family(english:"HP-UX Local Security Checks");

  script_dependencies("ssh_get_info.nasl");
  script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist");

  exit(0);
}


include("audit.inc");
include("global_settings.inc");
include("hpux.inc");


if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX");
if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING);

if (!hpux_check_ctx(ctx:"11.11"))
{
  exit(0, "The host is not affected since PHSS_34288 applies to a different OS release.");
}

patches = make_list("PHSS_34288", "PHSS_34835");
foreach patch (patches)
{
  if (hpux_installed(app:patch))
  {
    exit(0, "The host is not affected because patch "+patch+" is installed.");
  }
}


flag = 0;
if (hpux_check_patch(app:"Sup-Tool-Mgr.STM-CATALOGS", version:"B.11.11.16.09")) flag++;
if (hpux_check_patch(app:"Sup-Tool-Mgr.STM-SHLIBS", version:"B.11.11.16.09")) flag++;
if (hpux_check_patch(app:"Sup-Tool-Mgr.STM-UUT-RUN", version:"B.11.11.16.09")) flag++;


if (flag)
{
  if (report_verbosity > 0) security_warning(port:0, extra:hpux_report_get());
  else security_warning(0);
  exit(0);
}
else audit(AUDIT_HOST_NOT, "affected");

Oval

accepted2014-03-24T04:01:43.409-04:00
classvulnerability
contributors
  • nameMichael Wood
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
descriptionUnspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.
familyunix
idoval:org.mitre.oval:def:5627
statusaccepted
submitted2008-07-08T17:01:37.000-04:00
titleHP-UX running Support Tools Manager (xstm, cstm, stm) Local Denial of Service (DoS)
version39