English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

HP Server Automation Samba RPC Network Data Representation Marshalling Vulnerability


Secunia ID

SA49502

CVE-ID

CVE-2012-1182

Release Date

12 Jun 2012

Criticality

Moderately Critical

Solution Status

Vendor Patch

Software

HP Server Automation 7.x
HP Server Automation 9.x

Where

From local network

Impact
System access

This covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user.

Description

HP has acknowledged a vulnerability in HP Server Automation, which can be exploited by malicious people to compromise a vulnerable system.

For more information:
SA48742

The vulnerability is reported in versions 7.8.x, 9.0.x, and 9.1.x running on Red Hat Linux, SUSE Linux, and SunOS.

Solution

Apply HP Server Automation Patch SRVA_00127.
http://support.openview.hp.com/selfsolve/document/FID/DOCUMENTUM_SRVA_00127

Original Advisory

HPSBMU02790 SSRT100872:
http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c03366886