HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:54
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.3/AXP_DNVOSIECO03-V83.txt - | |
References | () http://secunia.com/advisories/33028 - Vendor Advisory | |
References | () http://securitytracker.com/id?1021364 - |
Information
Published : 2008-12-10 14:00
Updated : 2024-11-21 00:54
NVD link : CVE-2008-5417
Mitre link : CVE-2008-5417
CVE.ORG link : CVE-2008-5417
JSON object : View
Products Affected
hp
- openvms
- decnet_plus_for_openvms
CWE
CWE-264
Permissions, Privileges, and Access Controls