Description
HP-UX 11.11 and earlier allows local users to cause a denial of service (kernel deadlock), due to a "file system weakness" that is possibly via an mmap() system call and performing an I/O operation using data from the mapped buffer on the file descriptor for the mapped file.
Product(s):
- HP HP-UX 11.0.4
- HP-UX 11.00
- HP-UX 11.11
- HP hp-ux series 700 10.20
- HP hp-ux series 800 10.20
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2002-1668, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2002-1668 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.