Local Permission Bypass in HP DECnet-Plus for OpenVMS on Alpha Platform
CVE-2008-5417

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
10 December 2008

Summary

HP DECnet-Plus version 8.3 prior to ECO03 for OpenVMS on the Alpha platform is vulnerable due to world-writable permissions on the OSIT$NAMES logical name table. This flaw enables local users to circumvent intended access restrictions, permitting unauthorized modifications to the logical name table through the SYS$CRELNM and SYS$DELLNM system services.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.