[security bulletin] HPESBNS03702 rev.1 - HPE NonStop OSS Core Utilities with Bash Shell, Local Arbitrary Command Execution, Elevation of Privilege

LS0tLS1CRUdJTiBQR1AgU0lHTkVEIE1FU1NBR0UtLS0tLQpIYXNoOiBTSEEyNTYKCk5v
dGU6IHRoZSBjdXJyZW50IHZlcnNpb24gb2YgdGhlIGZvbGxvd2luZyBkb2N1bWVudCBp
cyBhdmFpbGFibGUgaGVyZToNCmh0dHBzOi8vaDIwNTY0Lnd3dzIuaHBlLmNvbS9ocHNj
L2RvYy9wdWJsaWMvZGlzcGxheT9kb2NJZD1lbXJfbmEtYzA1Mzg4MTE1DQoNClNVUFBP
UlQgQ09NTVVOSUNBVElPTiAtIFNFQ1VSSVRZIEJVTExFVElODQoNCkRvY3VtZW50IElE
OiBjMDUzODgxMTUNClZlcnNpb246IDENCg0KSFBFU0JOUzAzNzAyIHJldi4xIC0gSFBF
IE5vblN0b3AgT1NTIENvcmUgVXRpbGl0aWVzIHdpdGggQmFzaCBTaGVsbCwgTG9jYWwN
CkFyYml0cmFyeSBDb21tYW5kIEV4ZWN1dGlvbiwgRWxldmF0aW9uIG9mIFByaXZpbGVn
ZQ0KDQpOT1RJQ0U6IFRoZSBpbmZvcm1hdGlvbiBpbiB0aGlzIFNlY3VyaXR5IEJ1bGxl
dGluIHNob3VsZCBiZSBhY3RlZCB1cG9uIGFzDQpzb29uIGFzIHBvc3NpYmxlLg0KDQpS
ZWxlYXNlIERhdGU6IDIwMTctMDItMDkNCkxhc3QgVXBkYXRlZDogMjAxNy0wMi0wOQ0K
DQpQb3RlbnRpYWwgU2VjdXJpdHkgSW1wYWN0OiBMb2NhbDogQXJiaXRyYXJ5IENvbW1h
bmQgRXhlY3V0aW9uLCBFbGV2YXRpb24gb2YNClByaXZpbGVnZQ0KDQpTb3VyY2U6IEhl
d2xldHQgUGFja2FyZCBFbnRlcnByaXNlLCBQcm9kdWN0IFNlY3VyaXR5IFJlc3BvbnNl
IFRlYW0NCg0KVlVMTkVSQUJJTElUWSBTVU1NQVJZDQpTZXZlcmFsIHBvdGVudGlhbCBz
ZWN1cml0eSB2dWxuZXJhYmlsaXRpZXMgaGF2ZSBiZWVuIGRpc2NvdmVyZWQgaW4gdGhl
IEJhc2gNClNoZWxsIGluIE5vblN0b3AgT1NTIENvcmUgVXRpbGl0aWVzLiBUaGUgdnVs
bmVyYWJpbGl0aWVzIGFsbG93IGxvY2FsIHVzZXJzIHRvDQpleGVjdXRlIGFyYml0cmFy
eSBjb21tYW5kcyB3aXRoIHJvb3QgcHJpdmlsZWdlcy4NCg0KUmVmZXJlbmNlczoNCg0K
ICAtIENWRS0yMDE2LTc1NDMNCg0KU1VQUE9SVEVEIFNPRlRXQVJFIFZFUlNJT05TKjog
T05MWSBpbXBhY3RlZCB2ZXJzaW9ucyBhcmUgbGlzdGVkLg0KDQogIC0gTm9uU3RvcCBC
YXNoIEwgc2VyaWVzOiBUMTIwMkwwMSAtIFQxMjAyTDAxXkFBSTsgSiBhbmQgSCBzZXJp
ZXM6IFQxMjAySDAxDQotIC0gVDEyMDJIMDFeQUFHDQoNCkJBQ0tHUk9VTkQNCg0KICBD
VlNTIEJhc2UgTWV0cmljcw0KICA9PT09PT09PT09PT09PT09PQ0KICBSZWZlcmVuY2Us
IENWU1MgVjMgU2NvcmUvVmVjdG9yLCBDVlNTIFYyIFNjb3JlL1ZlY3Rvcg0KDQogICAg
Q1ZFLTIwMTYtNzU0Mw0KICAgICAgOC40IENWU1M6My4wL0FWOkwvQUM6TC9QUjpOL1VJ
Ok4vUzpVL0M6SC9JOkgvQTpIDQogICAgICA3LjIgKEFWOkwvQUM6TC9BdTpOL0M6Qy9J
OkMvQTpDKQ0KDQogICAgSW5mb3JtYXRpb24gb24gQ1ZTUyBpcyBkb2N1bWVudGVkIGlu
DQogICAgSFBFIEN1c3RvbWVyIE5vdGljZSBIUFNOLTIwMDgtMDAyIGhlcmU6DQoNCmh0
dHBzOi8vaDIwNTY0Lnd3dzIuaHBlLmNvbS9ocHNjL2RvYy9wdWJsaWMvZGlzcGxheT9k
b2NJZD1lbXJfbmEtYzAxMzQ1NDk5DQoNClJFU09MVVRJT04NCg0KSFBFIGhhcyBwcm92
aWRlZCB0aGUgZm9sbG93aW5nIHVwZGF0ZXMgdG8gcmVzb2x2ZSB0aGVzZSB2dWxuZXJh
YmlsaXRpZXMgaW4NCnRoZSBCYXNoIFNoZWxsIGluIEhQRSBOb25TdG9wIE9TUyBDb3Jl
IFV0aWxpdGllczoNCg0KICogTCBTZXJpZXM6IFQxMjAyTDAxXkFBSiAoT1NTIENvcmUg
VXRpbGl0aWVzKQ0KICogSiBTZXJpZXM6IFQxMjAySDAxXkFBSyAoT1NTIENvcmUgVXRp
bGl0aWVzKQ0KICogSCBTZXJpZXM6IFQxMjAySDAxXkFBSyAoT1NTIENvcmUgVXRpbGl0
aWVzKQ0KDQpSZWZlciB0byBOb25TdG9wIEhvdHN0dWZmIEhTMDMzNDUgZm9yIGFkZGl0
aW9uYWwgZGV0YWlscy4NCg0KSElTVE9SWQ0KVmVyc2lvbjoxIChyZXYuMSkgLSA5IEZl
YnJ1YXJ5IDIwMTcgSW5pdGlhbCByZWxlYXNlDQoNClRoaXJkIFBhcnR5IFNlY3VyaXR5
IFBhdGNoZXM6IFRoaXJkIHBhcnR5IHNlY3VyaXR5IHBhdGNoZXMgdGhhdCBhcmUgdG8g
YmUNCmluc3RhbGxlZCBvbiBzeXN0ZW1zIHJ1bm5pbmcgSGV3bGV0dCBQYWNrYXJkIEVu
dGVycHJpc2UgKEhQRSkgc29mdHdhcmUNCnByb2R1Y3RzIHNob3VsZCBiZSBhcHBsaWVk
IGluIGFjY29yZGFuY2Ugd2l0aCB0aGUgY3VzdG9tZXIncyBwYXRjaCBtYW5hZ2VtZW50
DQpwb2xpY3kuDQoNClN1cHBvcnQ6IEZvciBpc3N1ZXMgYWJvdXQgaW1wbGVtZW50aW5n
IHRoZSByZWNvbW1lbmRhdGlvbnMgb2YgdGhpcyBTZWN1cml0eQ0KQnVsbGV0aW4sIGNv
bnRhY3Qgbm9ybWFsIEhQRSBTZXJ2aWNlcyBzdXBwb3J0IGNoYW5uZWwuIEZvciBvdGhl
ciBpc3N1ZXMgYWJvdXQNCnRoZSBjb250ZW50IG9mIHRoaXMgU2VjdXJpdHkgQnVsbGV0
aW4sIHNlbmQgZS1tYWlsIHRvIHNlY3VyaXR5LWFsZXJ0QGhwZS5jb20uDQoNClJlcG9y
dDogVG8gcmVwb3J0IGEgcG90ZW50aWFsIHNlY3VyaXR5IHZ1bG5lcmFiaWxpdHkgZm9y
IGFueSBIUEUgc3VwcG9ydGVkDQpwcm9kdWN0Og0KICBXZWIgZm9ybTogaHR0cHM6Ly93
d3cuaHBlLmNvbS9pbmZvL3JlcG9ydC1zZWN1cml0eS12dWxuZXJhYmlsaXR5DQogIEVt
YWlsOiBzZWN1cml0eS1hbGVydEBocGUuY29tDQoNClN1YnNjcmliZTogVG8gaW5pdGlh
dGUgYSBzdWJzY3JpcHRpb24gdG8gcmVjZWl2ZSBmdXR1cmUgSFBFIFNlY3VyaXR5IEJ1
bGxldGluDQphbGVydHMgdmlhIEVtYWlsOiBodHRwOi8vd3d3LmhwZS5jb20vc3VwcG9y
dC9TdWJzY3JpYmVyX0Nob2ljZQ0KDQpTZWN1cml0eSBCdWxsZXRpbiBBcmNoaXZlOiBB
IGxpc3Qgb2YgcmVjZW50bHkgcmVsZWFzZWQgU2VjdXJpdHkgQnVsbGV0aW5zIGlzDQph
dmFpbGFibGUgaGVyZTogaHR0cDovL3d3dy5ocGUuY29tL3N1cHBvcnQvU2VjdXJpdHlf
QnVsbGV0aW5fQXJjaGl2ZQ0KDQpTb2Z0d2FyZSBQcm9kdWN0IENhdGVnb3J5OiBUaGUg
U29mdHdhcmUgUHJvZHVjdCBDYXRlZ29yeSBpcyByZXByZXNlbnRlZCBpbg0KdGhlIHRp
dGxlIGJ5IHRoZSB0d28gY2hhcmFjdGVycyBmb2xsb3dpbmcgSFBTQi4NCg0KM0MgPSAz
Q09NDQozUCA9IDNyZCBQYXJ0eSBTb2Z0d2FyZQ0KR04gPSBIUEUgR2VuZXJhbCBTb2Z0
d2FyZQ0KSEYgPSBIUEUgSGFyZHdhcmUgYW5kIEZpcm13YXJlDQpNVSA9IE11bHRpLVBs
YXRmb3JtIFNvZnR3YXJlDQpOUyA9IE5vblN0b3AgU2VydmVycw0KT1YgPSBPcGVuVk1T
DQpQViA9IFByb0N1cnZlDQpTVCA9IFN0b3JhZ2UgU29mdHdhcmUNClVYID0gSFAtVVgN
Cg0KQ29weXJpZ2h0IDIwMTYgSGV3bGV0dCBQYWNrYXJkIEVudGVycHJpc2UNCg0KSGV3
bGV0dCBQYWNrYXJkIEVudGVycHJpc2Ugc2hhbGwgbm90IGJlIGxpYWJsZSBmb3IgdGVj
aG5pY2FsIG9yIGVkaXRvcmlhbA0KZXJyb3JzIG9yIG9taXNzaW9ucyBjb250YWluZWQg
aGVyZWluLiBUaGUgaW5mb3JtYXRpb24gcHJvdmlkZWQgaXMgcHJvdmlkZWQNCiJhcyBp
cyIgd2l0aG91dCB3YXJyYW50eSBvZiBhbnkga2luZC4gVG8gdGhlIGV4dGVudCBwZXJt
aXR0ZWQgYnkgbGF3LCBuZWl0aGVyDQpIUCBvciBpdHMgYWZmaWxpYXRlcywgc3ViY29u
dHJhY3RvcnMgb3Igc3VwcGxpZXJzIHdpbGwgYmUgbGlhYmxlIGZvcg0KaW5jaWRlbnRh
bCxzcGVjaWFsIG9yIGNvbnNlcXVlbnRpYWwgZGFtYWdlcyBpbmNsdWRpbmcgZG93bnRp
bWUgY29zdDsgbG9zdA0KcHJvZml0czsgZGFtYWdlcyByZWxhdGluZyB0byB0aGUgcHJv
Y3VyZW1lbnQgb2Ygc3Vic3RpdHV0ZSBwcm9kdWN0cyBvcg0Kc2VydmljZXM7IG9yIGRh
bWFnZXMgZm9yIGxvc3Mgb2YgZGF0YSwgb3Igc29mdHdhcmUgcmVzdG9yYXRpb24uIFRo
ZQ0KaW5mb3JtYXRpb24gaW4gdGhpcyBkb2N1bWVudCBpcyBzdWJqZWN0IHRvIGNoYW5n
ZSB3aXRob3V0IG5vdGljZS4gSGV3bGV0dA0KUGFja2FyZCBFbnRlcnByaXNlIGFuZCB0
aGUgbmFtZXMgb2YgSGV3bGV0dCBQYWNrYXJkIEVudGVycHJpc2UgcHJvZHVjdHMNCnJl
ZmVyZW5jZWQgaGVyZWluIGFyZSB0cmFkZW1hcmtzIG9mIEhld2xldHQgUGFja2FyZCBF
bnRlcnByaXNlIGluIHRoZSBVbml0ZWQNClN0YXRlcyBhbmQgb3RoZXIgY291bnRyaWVz
LiBPdGhlciBwcm9kdWN0IGFuZCBjb21wYW55IG5hbWVzIG1lbnRpb25lZCBoZXJlaW4N
Cm1heSBiZSB0cmFkZW1hcmtzIG9mIHRoZWlyIHJlc3BlY3RpdmUgb3duZXJzLg0KLS0t
LS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0KVmVyc2lvbjogR251UEcgdjEKCmlRRWNC
QUVCQ0FBR0JRSlluSlVZQUFvSkVMWGhBeHQ3U1phaUdMTUgvMHJDTkZlM1pmNXlxT3or
Y1ZHOGZsMUgKNDRudzNZSHFmc1lXM2hDVml3Y0pzY01ycUdSaXVSbnlRZlhpTG9JYkRS
Z3JHM0dEaUJ6UFFIRUFVa2swbGMrdwpSNVYvMjBtMEdEL0JXSFllQkZWQkVtMzhHU0th
YVZxajg3c2I1WnhNdUZxMnJEUzRpNTVQWGk4cWp0S3diN0lxCkZQbk9objk0M2NGY0pS
RjBSTlpURVBrbmI4STh4WUpWQjVDUy9tOFhDMmlMVURvUm9rTHhDQmhhZTM0bklZb2YK
RHZHcS90UE84QjFPd0pTKzJHVkt0MWpjK014S2ZjTGpveE1PUzNOQjVnaVl5VVFBZWZu
dHdXS0hyYk5MYit4OAp0U2NRMS9scGs0YmU3Y2xCd2ZQbjQrNXZKbjRKRVhPaTFVNHdZ
dHkyY2haZVB5YnpBM3Jla3U4UkNQeE56cE09Cj1tYzlBCi0tLS0tRU5EIFBHUCBTSUdO
QVRVUkUtLS0tLQo=