![]() | ![]() |
|
|
Hewlett-Packard Company Information for VU#749342
Vendor Statement-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1 HP SECURITY BULLETIN HPSBGN01004 REVISION: 0 SSRT3614 - HP OpenCall Multiservice Controller (OCMC) DoS (Denial of Service) - -------------------------------------------------------------- NOTICE: There are no restrictions for distribution of this Bulletin provided that it remains complete and intact. The information in this Security bulletin should be acted upon as soon as possible. INITIAL RELEASE: 25 March 2004 POTENTIAL SECURITY IMPACT: Remote Denial of Service (DoS) SOURCE: HEWLETT-PACKARD COMPANY HP Software Security Response Team REFERENCES: CERT CA-2004-01, CISCO Advisory 47843 VULNERABILITY SUMMARY: A potential security vulnerability has been identified in the HP OpenCall MultiService Controller (OCMC) H.323 stack that may allow a remote user to create a Denial of Service (DoS). SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. All versions HP OCMC v1.2 and HP OCMC v1.1 for HP-UX 11.0 BACKGROUND: The HP Software Security Response team has contacted the source and various other vendors and is not aware of any malicious exploitation of any of the vulnerabilities described in this bulletin. A test suite developed by the U.K. National Infrastructure Security Co-ordination Centre (NISCC) and the University of Oulu Security Programming Group (OUSPG) has exposed vulnerabilities in several implementations of the H.323 protocol. The potential vulnerabilities may be exploited to produce a denial of service (DoS) attack. Such an attack may cause an affected product to failover or crash and failover. Due to its robust design OCMC will recover from most attack scenarios. In the event that OCMC does not recover, the attack can be stopped by blocking the offending IP address. Attacks may also be blocked by creating an access list to restrict TCP port 1720 traffic to known, trusted IP addresses. RESOLUTION: HP will be providing patches to the impacted versions of OCMC: OCMC v1.2 released January 2004 OCMC v1.1 patch 46 OCMC v1.1 patch 37 This bulletin will be revised as the patches become available and patches will be available from the normal HP Services support channel. Please write to security-alert@hp.com to request a PGP signed version of this bulletin. BULLETIN REVISION HISTORY: N/A * The software product category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number: GN=General, MA=Management Agents, MI=Misc. 3rd party, MP=HP-MPE/iX, NS=HP NonStop Servers, OV=HP OpenVMS, PI=HP Printing & Imaging, ST=HP Storage, TU=HP Tru64 UNIX, TL=Trusted Linux, UX=HP-UX, VV=VirtualVault SUPPORT: For further information, contact HP Services support channel. SUBSCRIBE: To initiate a subscription to receive future HP Security Bulletins via Email: http://h30046.www3.hp.com/driverAlertProfile.php +?regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driver +ITRC&topiccode=ITRC On the web page: Driver and Support Alerts/Notifications Sign-up: Product Selection Under Step1: your products 1. Select product category: - a minimum of servers must be selected. 2. Select product family or search: - a minimum of one product must be selected. 3. Add a product: - a minimum of one product must be added. In Step 2: your operating system(s) - check ALL operating systems for which alerts are required. Complete the form and Save.
As further information becomes available HP will provide notice of the availability of any necessary patches through standard security bulletin announcements and be available from your normal HP Services support channel. To report potential security vulnerabilities in HP software, send an E-mail message to: security-alert@hp.com.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||
![]() |
||||||||||||||||||||||