===============================================================================
Security Advisory                                                       CERT-NL
===============================================================================
Author/Source : CERT-NL (Teun Nijssen)                      Index  :    S-94-11
Distribution  : World                                       Page   :          1
Classification: External                                    Version:      Final
Subject       : Security Vulnerability in HP Vue 3.0        Date   :  22-Apr-94
===============================================================================

Synopsis:

_______________________________________________________________________________

PROBLEM:  Security vulnerability in HP-UX systems running HP Vue 3.0, only
PLATFORM: HP 9000 series 300/400/700/800 at HP-UX revision 9.X, only
DAMAGE:   Unauthorized root access
SOLUTION: Apply patch PHSS_4038 (700/800) or PHSS_4055 (300/400).
_______________________________________________________________________________


I.  Description

   A vulnerability has been discovered which allows non privileged
   users of HP 9000 series machines with models 300/400/700/800
   at HP-UX revision 9.X and running HP Vue 3.0 to obtain root
   privileges. Other versions of HP-UX and HP Vue do not have
   this vulnerability.

II. Solution

   HP has provided a patch to solve this problem. The description
   below comes from "HEWLETT-PACKARD SECURITY BULLETIN: #00008,
   19 April 1994"

-------------------------------------------------------------------------------
   A. Fixing the problem

      The problem can be fixed by applying patch PHSS_4038 (700/800)
      or PHSS_4055 (300/400).

   B. How to Install the Patch

   1.  Get a copy of the patch from one of the following locations:

       a. HP SupportLine Mail Service

       To obtain the patch, send the following in the TEXT PORTION
       OF THE MESSAGE to support@support.mayfield.hp.com
       (no Subject is required):

                send PHSS_4038

                or

                send PHSS_4055

       It will automatically be emailed back to you.  Note that
       users may also download the patch from HP SupportLine via
       ftp, kermit, or uucp.

       b. Response Center Support

       If you need additional assistance and have a support
       contract, you can contact your local Response Center for
       further help.

   2.  The patch information is current as of April 19, 1994.  You
       should list the patch:

             more PHSS_4038
             more PHSS_4055

       If it has been replaced there will be banner text saying:

                   OBSOLETE
                   REPLACED
                      BY
                   PHSS_NNNN


   3.  Apply the patch to your HP-UX system.  The complete instructions
       for applying the patch are in PHSS_40xx.text.

   4.  Examine /tmp/update.log for any relevant WARNINGs or ERRORs. This
       can be done as follows:

       a.  At the shell prompt, type "tail -60 /tmp/update.log | more"
       b.  Page through the next three screens via the space bar, looking
           for WARNING or ERROR messages.

----------------------------------------------------------------------

CERT-NL thanks Peter van Dijk of Erasmus University Rotterdam and the
programmers of the Hermes software of TNO and EUR for bringing this
information to our attention. CERT-NL also thanks Hewlett and Packard
for their activities to patch this vulnerability soon after its discovery.

==============================================================================
CERT-NL is the Computer Emergency Response Team, located in The
Netherlands. CERT-NL is a Full Member of the Forum of Incident Response
and Security Teams (FIRST). The constituency of CERT-NL are the SURFnet
connected institutions.
 
Past CERT-NL Security Bulletins and other CERT-NL related material can
be found on the anonymous FTP server of SURFnet bv:
"ftp.nic.surfnet.nl" [192.87.46.3], in the directory
"surfnet/net-security/cert-nl/docs/bulletin".  This information is also
available using email. Send an email saying "help" to
"mailserv@nic.surfnet.nl".
 
In case of computer or network security problems please contact CERT-NL
or the CERT of your own constituency. Please be aware of the fact that
we are one (when DST is in effect two) hour(s) ahead of Universal Time
Coordinated (i.e. UTC+0100 (UTC+0200)).
Email:     cert-nl@surfnet.nl
Phone:     +31 30 310290
Fax:       +31 30 340903
Snailmail: SURFnet bv
           Attn. CERT-NL
           P.O. Box 19035
           NL - 3501 DA  UTRECHT
           The Netherlands
A 7 * 24 hours phone number is available to SURFnet SSC's and FIRST
members on request.
==============================================================================
