SOFTPAQ NUMBER: SP14456 TITLE: Compaq Power Management Agents for NT 4.0 and Windows 2000 Server VERSION: 1.80 Rev B LANGUAGE: English CATEGORY: Drivers DIVISIONS: Industry Standard Server Group PRODUCTS AFFECTED: Compaq Power Management OPERATING SYSTEM: Windows NT 4.0 Windows 2000 SYSTEM CONFIGURATION: A computer running one of the operating systems listed above, that is running Compaq Power Management 1.8 or earlier. PREREQUISITES: Compaq Insight Management agents 3.20 or above. EFFECTIVE DATE: Immediate ELECTRONIC DISTRIBUTION ALLOWED: Yes SOFTPAQ UTILITY VERSION: 5.0 SUPERSEDES: N/A DESCRIPTION: This softpaq contains the Windows NT 4.0 / Windows 2000 Compaq Power Management Agents version 1.8B. This release is to fix a potential security issue in the web-enabled portion of the agent. The vulnerability can allow an attacker to either crash the web-enabled portion of the agent or alternatively execute some introduced code at the access level of the web-based management process. The only difference between version 1.8 and version 1.8B of the agents is CPQHMMO.DLL. The version of CPQHMMO.DLL should be 2.2 or greater to resolve this potential issue. The version number can be obtained by viewing the properties of the .DLL in the Windows File Explorer. Alternatively Softpaq SP14487 can be used to patch an existing system. SP14487 can be obtained from ftp.compaq.com. It is recommended that the patch in SP14487 be used regardless of your configuration to ensure that all web enabled agents in other Compaq applications are updated to the most current CPQHMMO.DLL. If you are running a version of Compaq Power Management less than 1.8, this softpaq can also be used to upgrade to the most current version Compaq Power Management. Note that if you upgrade to version 1.8 of the agents you should also upgrade the management console application to version 1.8 as well. Enhancements/Fixes: This release is to fix a potential security issue in the web-enabled portion of the agent. HOW TO USE: 1. Download the SoftPaq into a directory and change to that directory. The file that is downloaded is an executable with a filename based on the SoftPaq Number above. 2. From that drive and directory, execute the downloaded file. Change to the directory that contains the expanded files and launch Setup.exe. Follow the on-screen instructions to install the program. 3. After the program is installed the softpaq and all installation files expanded in the directory in step 1 can be deleted. Copyright 2001, Compaq Computer Corporation. All rights reserved. Product names mentioned herein may be trademarks and/or registered trademarks of their respective companies.