HP OpenVMS Local Password Disclosure Vulnerability
BID:19783
CVE-2006-4537 |Info
HP OpenVMS Local Password Disclosure Vulnerability
| Bugtraq ID: | 19783 |
| Class: | Design Error |
| CVE: |
CVE-2006-4537 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 30 2006 12:00AM |
| Updated: | Jun 26 2007 04:18AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
HP OpenVMS 7.3 -2 Alpha HP OpenVMS 8.2.Alpha |
| Not Vulnerable: | |
Discussion
HP OpenVMS Local Password Disclosure Vulnerability
OpenVMS is prone to a local password-disclosure vulnerability.
Exploiting this vulnerability may allow local attackers to access user passwords. Sensitive information gathered using this attack can lead to other attacks against the computer.
OpenVMS ALPHA V7.3-2 and ALPHA V8.2 are reported vulnerable.
OpenVMS is prone to a local password-disclosure vulnerability.
Exploiting this vulnerability may allow local attackers to access user passwords. Sensitive information gathered using this attack can lead to other attacks against the computer.
OpenVMS ALPHA V7.3-2 and ALPHA V8.2 are reported vulnerable.
Exploit / POC
HP OpenVMS Local Password Disclosure Vulnerability
Attackers can exploit this issue using utilities provided with the operating system.
Attackers can exploit this issue using utilities provided with the operating system.
Solution / Fix
HP OpenVMS Local Password Disclosure Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
HP OpenVMS 8.2.Alpha
HP OpenVMS 7.3 -2 Alpha
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
HP OpenVMS 8.2.Alpha
-
HP AXP_DNVOSIECO02-V82.PCSI-DCX_AXPEXE
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.2/AXP_DNVOSIECO02-V82.P CSI-DCX_AXPEXE
HP OpenVMS 7.3 -2 Alpha
-
HP AXP_DNVOSIECO03-V732.PCSI-DCX_AXPEXE
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIECO03-V73 2.PCSI-DCX_AXPEXE
References
HP OpenVMS Local Password Disclosure Vulnerability
References:
References: