涉及程序: ovactiond 详细: ovactiond 是 OpenView ( http://www.openview.hp.com/ ) 和 NetView ( http://www.tivoli.com/products/index/netview/ ) 的一个组件,它能用来管理大型系统和网络。发现它存在严重漏洞,利用此漏洞,攻击者能取得受影响机器管理员权限。 ovactind 是用于 OpenView 和 NetViewr 的 SNMP 陷阱和事件处理器(event handler),但是发现它存在漏洞,攻击者构造特殊请求发往受影响管理服务器,将能取得 ovationd 进程特权。 在 UNIX 系统上,ovactind 是以 bin 身份运行的,攻击者取得 bin 后,有可能进一步取得 root 特权。在 WINDOWS 系统上,ovactind 是以 Local System 身份运行的。 更为严重的是,运行这种产品的系统同其它网络设备之间通常存在信任关系,攻击者如果取得一个机器的特权,是完全可能会威胁到其它机器安全的。 受影响系统: Systems running HP OpenView Network Node Manager (NNM) Version 6.1 on the following platforms: HP9000 Servers running HP-UX releases 10.20 and 11.00 (only) Sun Microsystems Solaris releases 2.x Microsoft Windows NT4.x / Windows 2000 Systems running Tivoli NetView Versions 5.x and 6.x on the following platforms: IBM AIX Sun Microsystems Solaris Compaq Tru64 Unix Microsoft Windows NT4.x / Windows 2000 解决方案: 下载安装补丁: HP http://us-support.external.hp.com/cki/bin/doc.pl/screen=ckiDisplayDocument?docId=200000055277985 http://www.kb.cert.org/vuls/id/952171 Tivoli http://www.tivoli.com/support/