PT-2018-6522 · Hewlett Packard · Openvms+2
Simon Clubley
·
Publicado
2018-02-07
·
Atualizado
2018-08-13
·
CVE-2017-17482
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
OpenVMS versions prior to V8.4-2L2 on Alpha
OpenVMS versions prior to V8.4-2L1 on IA64
VAX/VMS versions 4.0 and later
Description:
A malformed DCL command table may result in a buffer overflow, allowing a local privilege escalation when a non-privileged account enters a crafted command line. This issue is exploitable on VAX and Alpha and may cause a process crash on IA64.
Recommendations:
For OpenVMS versions prior to V8.4-2L2 on Alpha, update to version V8.4-2L2 or later to resolve the issue.
For OpenVMS versions prior to V8.4-2L1 on IA64, update to version V8.4-2L1 or later to resolve the issue.
For VAX/VMS versions 4.0 and later, consider restricting access to the DCL command table to minimize the risk of exploitation until a patch is available.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dcl
Openvms
Vax/Vms