PT-2003-1246 · Hewlett Packard · Ucx+2
Published
2003-04-02
·
Updated
2008-09-05
·
CVE-2002-1513
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
HP TCP/IP services for OpenVMS versions 4.2 through 5.3
Description
The issue allows local users to truncate arbitrary files due to the UCX POP server running with SYSPRV and BYPASS privileges, which overrides file system permissions. This can be achieved via the -logfile command line option.
Recommendations
For HP TCP/IP services for OpenVMS versions 4.2 through 5.3, consider restricting access to the -logfile command line option to prevent unauthorized file truncation until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Tcp/Ip Services For Openvms
Openvms
Ucx