PT-2003-1246 · Hewlett Packard · Ucx+2
Publicado
2003-04-02
·
Atualizado
2008-09-05
·
CVE-2002-1513
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HP TCP/IP services for OpenVMS versions 4.2 through 5.3
Description
The issue allows local users to truncate arbitrary files due to the UCX POP server running with SYSPRV and BYPASS privileges, which overrides file system permissions. This can be achieved via the -logfile command line option.
Recommendations
For HP TCP/IP services for OpenVMS versions 4.2 through 5.3, consider restricting access to the -logfile command line option to prevent unauthorized file truncation until a fix is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hp Tcp/Ip Services For Openvms
Openvms
Ucx