HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2008-12-10 06:00
Updated : 2011-01-04 21:00
NVD link : CVE-2008-5417
Mitre link : CVE-2008-5417
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
hp
- decnet_plus_for_openvms
- openvms