|
This document summarizes the contents and special instructions
for the Tru64 UNIX Insight Management Agents components
contained in this kit. For information about installing
or removing patches, and general patch management, execute
the im_patch file which is part of the patch-kit.
1) This Patch Kit Distribution contains:
The 'Management HTTP Server' with various SSRT fixes
and uses SSL library version: OpenSSL 0.9.6m
The patch-kit CPQIM320.HTTP.03 includes all the SSRT
fixes from the previous patch-kits CPQIM320.HTTP.01 and
CPQIM320.HTTP.02.
The components in this kit are being released early
for general customer use. Components in this kit are
installed by running im_patch from the directory in which
the kit was untarred.
2) Special Instructions: If this patch kit is being
installed on a cluster, it is sufficient to do so on
only one of the nodes. But in order for the patch to
take effect on the other nodes, the agents have to be
manually re-started. On all other nodes run the following
commands:
#/sbin/init.d/snmpd stop
#/sbin/init.d/insightd stop
#/sbin/init.d/snmpd start
#/sbin/init.d/insightd start
3) Summary of Insight Management patch components contained in this
kit:
PatchId Summary Of Fix
---------------- ------------------------------------------------------
CPQIM320.HTTP.03 libcpqhmmo.so built with openssl library version 9.6m
4) Additional information from Engineering
The 'Management HTTP Server' has various SSRT fixes and uses SSL library
version openssl 9.6m. A potential security vulnerability has been identified
in the HP Tru64 UNIX SSL library used by Insight Manager Web
Agent (insightd). The potential vulnerability may be remotely exploitable,
resulting in a denial of service (DoS).
HP has corrected the following potential security vulnerability:
SSRT4717 - SSL (Severity - High) SSL=Secure Sockets Layer
The patch-kit CPQIM320.HTTP.03 is cumulative, and it includes all the
SSRT fixes from the previous patch-kits.
5) Affected files: This patch delivers the following files:
/var/shlib/libcpqhmmo.so
/var/opt/CPQIM320/bin/libcpqhmmo.so
Copyright Hewlett-Packard Company 2004. All Rights reserved
|