CVE-2008-5417
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD
Description
HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services.
Affected (1)
Products: Hp: Decnet Plus For Openvms
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.3 |
| Running on/with | Platform Versions |
|---|---|
Hp Openvms | Version 8.3 |
Related CWEs
References (6)
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.3/AXP_DNVOSIECO03-V83.txt (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.3/AXP_DNVOSIECO03-V83.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.