PT-2003-1246 · Hewlett Packard · Ucx+2

Published

2003-04-02

·

Updated

2008-09-05

·

CVE-2002-1513

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HP TCP/IP services for OpenVMS versions 4.2 through 5.3
Description The issue allows local users to truncate arbitrary files due to the UCX POP server running with SYSPRV and BYPASS privileges, which overrides file system permissions. This can be achieved via the -logfile command line option.
Recommendations For HP TCP/IP services for OpenVMS versions 4.2 through 5.3, consider restricting access to the -logfile command line option to prevent unauthorized file truncation until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1513

Affected Products

Hp Tcp/Ip Services For Openvms
Openvms
Ucx