PT-2007-6325 · Hewlett Packard · Hp Openvms

Published

2007-10-06

·

Updated

2011-03-08

·

CVE-2007-5242

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: HP OpenVMS versions 8.3 and earlier
Description: The issue allows remote attackers to cause a denial of service, resulting in a machine crash, by sending an "oversize" packet. This occurs because the packet is not properly discarded if the device has no remaining buffers after receipt of the first buffer segment.
Recommendations: For HP OpenVMS versions 8.3 and earlier, consider implementing packet size restrictions to prevent the receipt of oversize packets until a fix is available. As a temporary workaround, monitor system resources closely to quickly identify and respond to potential denial-of-service attempts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-5242

Affected Products

Hp Openvms