**************************** MUP SUMMARY INFORMATION **************************** Kit Name: ALPVMSMUP01_062.A Kit Applies To: OpenVMS ALPHA V6.2 Approximate Kit Size: 342 blocks Installation Rating: INSTALL_1 Superseded Kits: None. Mandatory Kit Dependencies: VMS62TO71U2_PCSI.V0200 Optional Kit Dependencies: DEC-AXPVMS-DNVOSIMUP01-V0603--4.PCSI Compressed ALPVMSMUP01_062.A-DCX_AXPEXE Kit Checksum: 2363846848 ======================================================================= Hewlett-Packard OpenVMS MUP Cover Letter ======================================================================= MUP NUMBER: ALPVMSMUP01_062 PRODUCT: OpenVMS Alpha OPERATING SYSTEM V6.2 UPDATE PRODUCT: OpenVMS Alpha OPERATING SYSTEM V6.2 1 KIT NAME: ALPVMSMUP01_062 2 KIT DESCRIPTION: 2.1 Installation Rating: INSTALL_1 : To be installed by all customers. This installation rating, based upon current CLD information, is provided to serve as a guide to which customers should apply this remedial kit. (Reference attached Disclaimer of Warranty and Limitation of Liability Statement) 2.2 Reboot Requirement: Reboot Required. HP strongly recommends that a reboot is performed immediately after kit installation to avoid system instability. If you have other nodes in your OpenVMS cluster, they must also be rebooted in order to make use of the new image(s). If it is not possible or convenient to reboot the entire cluster at this time, a rolling re-boot may be performed. 2.3 Version(s) of OpenVMS to which this kit may be applied: OpenVMS Alpha V6.2, V6.2-1H1, V6.2-1H2, V6.2-1H3 2.4 New functionality or new hardware support provided: No. 3 KITS SUPERSEDED BY THIS KIT: - None. 4 KIT DEPENDENCIES: 4.1 The following remedial kit(s), or later, must be installed BEFORE installation of this, or any required kit: - VMS62TO71U2_PCSI.V0200 Page 2 4.2 In order to receive all the corrections listed in this kit, the following remedial kits, or later, should also be installed: - DEC-AXPVMS-DNVOSIMUP01-V0603--4.PCSI 5 FILES PATCHED OR REPLACED: o [SYSLIB]DECW$SESSIONSHRP.EXE (new image) Image Identification Information image name: "DECW$SESSIONSHRP" image file identification: "DW T6.2-970429" image file build identification: "" link date/time: 22-OCT-2004 11:25:51.93 linker identification: "A11-20" Overall Image Checksum: 1003724758 6 NEW FUNCTIONALITY AND/OR PROBLEMS ADDRESSED IN THE ALPVMSMUP01_062 KIT 6.1 New functionality addressed in this kit None. 6.2 Problems addressed in this kit 6.2.1 Potential security vulnerability. 6.2.1.1 Problem Description: HP has determined that systems running OpenVMS VAX or Alpha Version V7.* or V6.* have a potential security vulnerability. This vulnerability could be exploited allowing for an unintended privileged access to data and system resources. To protect against this potential security risk, HP is making a mandatory update patch available for OpenVMS customers. This patch is provided by installing this ALPVMSMUP01_062 kit and the AXP_DNVOSIMUP01-V0603 kit. To fully install this Security MUP, DECnet Phase V customers must install both of these kits. Note that OpenVMS V8.2 and VAX Version 5.* customers are not subject to this potential security vulnerability. Images Affected: Page 3 - [SYSLIB]DECW$SESSIONSHRP.EXE 6.2.1.2 CLDs, and QARs reporting this problem: 6.2.1.2.1 CLD(s) None. 6.2.1.2.2 QAR(s) None. 6.2.1.3 Problem Analysis: See Problem Description 6.2.1.4 Release Version of OpenVMS that will contain this change: OpenVMS Alpha and I64 V8.2 6.2.1.5 Work-arounds: None. 7 INSTALLATION INSTRUCTIONS 7.1 Compressed File This kit is provided as a DCX compressed kit. To expand this file to the installable VMSINSTAL file, run the file with a RUN file_name command. When the file is run you will see the following output: $ RUN ALPVMSMUP01_062.A-DCX_AXPEXE FTSV DCX auto-extractible compressed file for OpenVMS (AXP) FTSV V3.0 -- FTSV$DCX_AXP_AUTO_EXTRACT Copyright (c) Digital Equipment Corp. 1993 Options: [output_file_specification] [input_file_specification] The decompressor needs to know the filename to use for the decompressed file. If you don't specify any, it will use the original name of the file before it was compressed, and create it in the current directory. If you specify a directory name, the file will be created in that directory. Decompress into (file specification): Page 4 If you want the file to be expanded into a different directory, enter the directory specification. DO NOT enter a new file name. The expanded file must retain the original name. If you want to expand the file via batch, the command file must contain an answer to the Decompress into "(file specification)" question, either a or an alternate directory specification 7.2 Installation Command Install this kit with the VMSINSTAL utility by logging into the SYSTEM account, and typing the following at the DCL prompt: @SYS$UPDATE:VMSINSTAL ALPVMSMUP01_062 The saveset location may be a tape drive, CD, or a disk directory that contains the kit saveset. 8 COPYRIGHT AND DISCLAIMER: (C) Copyright 2004 Hewlett-Packard Development Company, L.P. Confidential computer software. Valid license from HP and/or its subsidiaries required for possession, use, or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license. Neither HP nor any of its subsidiaries shall be liable for technical or editorial errors or omissions contained herein. The information in this document is provided "as is" without warranty of any kind and is subject to change without notice. The warranties for HP products are set forth in the express limited warranty statements accompanying such products. Nothing herein should be construed as constituting an additional warranty. DISCLAIMER OF WARRANTY AND LIMITATION OF LIABILITY THIS PATCH IS PROVIDED AS IS, WITHOUT WARRANTY OF ANY KIND. ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY EXCLUDED TO THE EXTENT PERMITTED BY APPLICABLE LAW. IN NO EVENT WILL HP BE LIABLE FOR ANY LOST REVENUE OR PROFIT, OR FOR SPECIAL, INDIRECT, CONSEQUENTIAL, INCIDENTAL OR PUNITIVE DAMAGES, HOWEVER CAUSED AND REGARDLESS OF THE THEORY OF LIABILITY, WITH RESPECT TO ANY PATCH MADE AVAILABLE HERE OR TO THE USE OF SUCH PATCH.