Vulnerabilities > CVE-2009-2679 - Remote Denial Of Service vulnerability in HP Hp-Ux B.11.11/B.11.23/B.11.31

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
hp
nessus

Summary

Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.

Vulnerable Configurations

Part Description Count
OS
Hp
3

Nessus

  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_39443.NASL
    descriptions700_800 11.31 bootpd(1M)/DHCP, tftp(1) and tftpd(1M) patch : A potential security vulnerability has been identified with HP-UX running bootpd. The vulnerability could be exploited remotely to create a Denial of Service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id41024
    published2009-09-21
    reporterThis script is Copyright (C) 2009-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/41024
    titleHP-UX PHNE_39443 : HP-UX Running bootpd, Remote Denial of Service (DoS) (HPSBUX02458 SSRT090104 rev.1)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and patch checks in this plugin were 
    # extracted from HP patch PHNE_39443. The text itself is
    # copyright (C) Hewlett-Packard Development Company, L.P.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(41024);
      script_version("1.11");
      script_cvs_date("Date: 2018/08/10 18:07:07");
    
      script_cve_id("CVE-2009-2679");
      script_xref(name:"HP", value:"emr_na-c01866324");
      script_xref(name:"HP", value:"HPSBUX02458");
      script_xref(name:"HP", value:"SSRT090104");
    
      script_name(english:"HP-UX PHNE_39443 : HP-UX Running bootpd, Remote Denial of Service (DoS) (HPSBUX02458 SSRT090104 rev.1)");
      script_summary(english:"Checks for the patch in the swlist output");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote HP-UX host is missing a security-related patch."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "s700_800 11.31 bootpd(1M)/DHCP, tftp(1) and tftpd(1M) patch : 
    
    A potential security vulnerability has been identified with HP-UX
    running bootpd. The vulnerability could be exploited remotely to
    create a Denial of Service (DoS)."
      );
      # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01866324
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?617e5452"
      );
      script_set_attribute(
        attribute:"solution", 
        value:"Install patch PHNE_39443 or subsequent."
      );
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux");
    
      script_set_attribute(attribute:"patch_publication_date", value:"2009/09/15");
      script_set_attribute(attribute:"plugin_publication_date", value:"2009/09/21");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2009-2018 Tenable Network Security, Inc.");
      script_family(english:"HP-UX Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("hpux.inc");
    
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX");
    if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    if (!hpux_check_ctx(ctx:"11.31"))
    {
      exit(0, "The host is not affected since PHNE_39443 applies to a different OS release.");
    }
    
    patches = make_list("PHNE_39443", "PHNE_42689");
    foreach patch (patches)
    {
      if (hpux_installed(app:patch))
      {
        exit(0, "The host is not affected because patch "+patch+" is installed.");
      }
    }
    
    
    flag = 0;
    if (hpux_check_patch(app:"DHCPv4.DHC4-ENG-A-MAN", version:"B.11.31")) flag++;
    if (hpux_check_patch(app:"DHCPv4.DHCPV4-RUN", version:"B.11.31")) flag++;
    
    
    if (flag)
    {
      if (report_verbosity > 0) security_hole(port:0, extra:hpux_report_get());
      else security_hole(0);
      exit(0);
    }
    else audit(AUDIT_HOST_NOT, "affected");
    
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_39700.NASL
    descriptions700_800 11.11 bootpd(1M)/DHCP, tftp(1) and tftpd(1M) patch : A potential security vulnerability has been identified with HP-UX running bootpd. The vulnerability could be exploited remotely to create a Denial of Service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id41026
    published2009-09-21
    reporterThis script is Copyright (C) 2009-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/41026
    titleHP-UX PHNE_39700 : HP-UX Running bootpd, Remote Denial of Service (DoS) (HPSBUX02458 SSRT090104 rev.1)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and patch checks in this plugin were 
    # extracted from HP patch PHNE_39700. The text itself is
    # copyright (C) Hewlett-Packard Development Company, L.P.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(41026);
      script_version("1.9");
      script_cvs_date("Date: 2018/08/10 18:07:07");
    
      script_cve_id("CVE-2009-2679");
      script_xref(name:"HP", value:"emr_na-c01866324");
      script_xref(name:"HP", value:"HPSBUX02458");
      script_xref(name:"HP", value:"SSRT090104");
    
      script_name(english:"HP-UX PHNE_39700 : HP-UX Running bootpd, Remote Denial of Service (DoS) (HPSBUX02458 SSRT090104 rev.1)");
      script_summary(english:"Checks for the patch in the swlist output");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote HP-UX host is missing a security-related patch."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "s700_800 11.11 bootpd(1M)/DHCP, tftp(1) and tftpd(1M) patch : 
    
    A potential security vulnerability has been identified with HP-UX
    running bootpd. The vulnerability could be exploited remotely to
    create a Denial of Service (DoS)."
      );
      # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01866324
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?617e5452"
      );
      script_set_attribute(
        attribute:"solution", 
        value:"Install patch PHNE_39700 or subsequent."
      );
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux");
    
      script_set_attribute(attribute:"patch_publication_date", value:"2009/09/15");
      script_set_attribute(attribute:"plugin_publication_date", value:"2009/09/21");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2009-2018 Tenable Network Security, Inc.");
      script_family(english:"HP-UX Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("hpux.inc");
    
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX");
    if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    if (!hpux_check_ctx(ctx:"11.11"))
    {
      exit(0, "The host is not affected since PHNE_39700 applies to a different OS release.");
    }
    
    patches = make_list("PHNE_39700");
    foreach patch (patches)
    {
      if (hpux_installed(app:patch))
      {
        exit(0, "The host is not affected because patch "+patch+" is installed.");
      }
    }
    
    
    flag = 0;
    if (hpux_check_patch(app:"InternetSrvcs.INET-ENG-A-MAN", version:"B.11.11")) flag++;
    if (hpux_check_patch(app:"InternetSrvcs.INETSVCS-BOOT", version:"B.11.11")) flag++;
    if (hpux_check_patch(app:"InternetSrvcs.INETSVCS-INC", version:"B.11.11")) flag++;
    
    
    if (flag)
    {
      if (report_verbosity > 0) security_hole(port:0, extra:hpux_report_get());
      else security_hole(0);
      exit(0);
    }
    else audit(AUDIT_HOST_NOT, "affected");
    
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHNE_39668.NASL
    descriptions700_800 11.23 bootpd(1M)/DHCP, tftp(1) and tftpd(1M) patch : A potential security vulnerability has been identified with HP-UX running bootpd. The vulnerability could be exploited remotely to create a Denial of Service (DoS).
    last seen2020-06-01
    modified2020-06-02
    plugin id41025
    published2009-09-21
    reporterThis script is Copyright (C) 2009-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/41025
    titleHP-UX PHNE_39668 : HP-UX Running bootpd, Remote Denial of Service (DoS) (HPSBUX02458 SSRT090104 rev.1)
    code
    #
    # (C) Tenable Network Security, Inc.
    #
    # The descriptive text and patch checks in this plugin were 
    # extracted from HP patch PHNE_39668. The text itself is
    # copyright (C) Hewlett-Packard Development Company, L.P.
    #
    
    include("compat.inc");
    
    if (description)
    {
      script_id(41025);
      script_version("1.13");
      script_cvs_date("Date: 2018/08/10 18:07:07");
    
      script_cve_id("CVE-2009-2679");
      script_xref(name:"HP", value:"emr_na-c01866324");
      script_xref(name:"HP", value:"HPSBUX02458");
      script_xref(name:"HP", value:"SSRT090104");
    
      script_name(english:"HP-UX PHNE_39668 : HP-UX Running bootpd, Remote Denial of Service (DoS) (HPSBUX02458 SSRT090104 rev.1)");
      script_summary(english:"Checks for the patch in the swlist output");
    
      script_set_attribute(
        attribute:"synopsis", 
        value:"The remote HP-UX host is missing a security-related patch."
      );
      script_set_attribute(
        attribute:"description", 
        value:
    "s700_800 11.23 bootpd(1M)/DHCP, tftp(1) and tftpd(1M) patch : 
    
    A potential security vulnerability has been identified with HP-UX
    running bootpd. The vulnerability could be exploited remotely to
    create a Denial of Service (DoS)."
      );
      # http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01866324
      script_set_attribute(
        attribute:"see_also",
        value:"http://www.nessus.org/u?617e5452"
      );
      script_set_attribute(
        attribute:"solution", 
        value:"Install patch PHNE_39668 or subsequent."
      );
      script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C");
    
      script_set_attribute(attribute:"plugin_type", value:"local");
      script_set_attribute(attribute:"cpe", value:"cpe:/o:hp:hp-ux");
    
      script_set_attribute(attribute:"patch_publication_date", value:"2009/09/15");
      script_set_attribute(attribute:"plugin_publication_date", value:"2009/09/21");
      script_end_attributes();
    
      script_category(ACT_GATHER_INFO);
      script_copyright(english:"This script is Copyright (C) 2009-2018 Tenable Network Security, Inc.");
      script_family(english:"HP-UX Local Security Checks");
    
      script_dependencies("ssh_get_info.nasl");
      script_require_keys("Host/local_checks_enabled", "Host/HP-UX/version", "Host/HP-UX/swlist");
    
      exit(0);
    }
    
    
    include("audit.inc");
    include("global_settings.inc");
    include("hpux.inc");
    
    
    if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED);
    if (!get_kb_item("Host/HP-UX/version")) audit(AUDIT_OS_NOT, "HP-UX");
    if (!get_kb_item("Host/HP-UX/swlist")) audit(AUDIT_PACKAGE_LIST_MISSING);
    
    if (!hpux_check_ctx(ctx:"11.23"))
    {
      exit(0, "The host is not affected since PHNE_39668 applies to a different OS release.");
    }
    
    patches = make_list("PHNE_39668", "PHNE_43157", "PHNE_43602", "PHNE_43893", "PHNE_44180");
    foreach patch (patches)
    {
      if (hpux_installed(app:patch))
      {
        exit(0, "The host is not affected because patch "+patch+" is installed.");
      }
    }
    
    
    flag = 0;
    if (hpux_check_patch(app:"InternetSrvcs.INET-ENG-A-MAN", version:"B.11.23")) flag++;
    if (hpux_check_patch(app:"InternetSrvcs.INETSVCS2-BOOT", version:"B.11.23")) flag++;
    
    
    if (flag)
    {
      if (report_verbosity > 0) security_hole(port:0, extra:hpux_report_get());
      else security_hole(0);
      exit(0);
    }
    else audit(AUDIT_HOST_NOT, "affected");
    

Oval

accepted2015-04-20T04:02:27.706-04:00
classvulnerability
contributors
  • namePai Peng
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
  • namePrashant Kumar
    organizationHewlett-Packard
  • nameMike Cokus
    organizationThe MITRE Corporation
descriptionUnspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.
familyunix
idoval:org.mitre.oval:def:5780
statusaccepted
submitted2009-09-16T13:58:26.000-04:00
titleHP-UX Running bootpd, Remote Denial of Service (DoS)
version46

Seebug

bulletinFamilyexploit
descriptionBugraq ID: 36395 CVE ID:CVE-2009-2679 HP-UX是一款商业性质的操作系统。 HP-UX bootpd存在一个未明错误,远程攻击者可以利用漏洞对此服务程序进行拒绝服务攻击。 目前没有详细漏洞细节提供。 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 厂商解决方案 用户可联系供应商下载安装如下补丁: HP HP-UX B.11.31 HP PHNE_39443 http://itrc.hp.com HP HP-UX B.11.23 HP PHNE_39668 http://itrc.hp.com
idSSV:12347
last seen2017-11-19
modified2009-09-18
published2009-09-18
reporterRoot
titleHP-UX bootpd远程拒绝服务漏洞