PT-2007-6325 · Hewlett Packard · Hp Openvms
Published
2007-10-06
·
Updated
2011-03-08
·
CVE-2007-5242
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
HP OpenVMS versions 8.3 and earlier
Description:
The issue allows remote attackers to cause a denial of service, resulting in a machine crash, by sending an "oversize" packet. This occurs because the packet is not properly discarded if the device has no remaining buffers after receipt of the first buffer segment.
Recommendations:
For HP OpenVMS versions 8.3 and earlier, consider implementing packet size restrictions to prevent the receipt of oversize packets until a fix is available. As a temporary workaround, monitor system resources closely to quickly identify and respond to potential denial-of-service attempts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Openvms