Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-5417

Overview

Vulnerability Score 2.1 2.1
CVE Id CVE-2008-5417
Last Modified 05 Jan 2011 12:00:00
Published 10 Dec 2008 09:00:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2008-5417

Summary

HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services.

Vulnerable Systems

Application

  • Hp Decnet Plus For Openvms 8.3


References

SECTRACK - 1021364

SECUNIA - 33028

CONFIRM - ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.3/AXP_DNVOSIECO03-V83.txt


Last Updated: 27 May 2016 10:48:48