← Back

CVE-2008-5417

nvd nist
Published: Dec 10, 2008Modified: Apr 23, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services.

Affected (1)

1 product
Decnet Plus For Openvms
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 8.3
Running on/withPlatform Versions
Hp
Openvms
Version 8.3

Related CWEs

References (6)

ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.3/AXP_DNVOSIECO03-V83.txt (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.3/AXP_DNVOSIECO03-V83.txt (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.