PT-2008-5276 · Hewlett Packard · Hp Tcp/Ip Services For Openvms
Published
2008-09-05
·
Updated
2017-08-08
·
CVE-2008-3946
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HP TCP/IP Services for OpenVMS version 5.x
Description
The issue allows local users to read arbitrary files. This is achieved through a link corresponding to a
.plan or .project file in the finger client.Recommendations
For HP TCP/IP Services for OpenVMS version 5.x, consider restricting access to the finger client until a fix is available. As a temporary workaround, limit the ability of local users to create links to
.plan or .project files.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Tcp/Ip Services For Openvms