Required CVE Record Information
Description
The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.
References 5 Total
- securityfocus.com: 5790 vdb-entry
- iss.net: openvms-pop-gain-privileges(10236) vdb-entry
- online.securityfocus.com: 20020927 OpenVMS POP server local vulnerability mailing-list
- archives.neohapsis.com: 20021001 [security bulletin] SSRT2371 HP OpenVMS Potential POP server local vulnerability (fwd) mailing-list
- archives.neohapsis.com: SSRT2371 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 5 Total
- securityfocus.com: 5790 vdb-entryx_transferred
- iss.net: openvms-pop-gain-privileges(10236) vdb-entryx_transferred
- online.securityfocus.com: 20020927 OpenVMS POP server local vulnerability mailing-listx_transferred
- archives.neohapsis.com: 20021001 [security bulletin] SSRT2371 HP OpenVMS Potential POP server local vulnerability (fwd) mailing-listx_transferred
- archives.neohapsis.com: SSRT2371 vendor-advisoryx_transferred