PT-2018-6522 · Hewlett Packard · Openvms+2

Simon Clubley

·

Published

2018-02-07

·

Updated

2018-08-13

·

CVE-2017-17482

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OpenVMS versions prior to V8.4-2L2 on Alpha OpenVMS versions prior to V8.4-2L1 on IA64 VAX/VMS versions 4.0 and later
Description: A malformed DCL command table may result in a buffer overflow, allowing a local privilege escalation when a non-privileged account enters a crafted command line. This issue is exploitable on VAX and Alpha and may cause a process crash on IA64.
Recommendations: For OpenVMS versions prior to V8.4-2L2 on Alpha, update to version V8.4-2L2 or later to resolve the issue. For OpenVMS versions prior to V8.4-2L1 on IA64, update to version V8.4-2L1 or later to resolve the issue. For VAX/VMS versions 4.0 and later, consider restricting access to the DCL command table to minimize the risk of exploitation until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17482

Affected Products

Dcl
Openvms
Vax/Vms