VMS Monitor Vulnerability
BID:51
Info
VMS Monitor Vulnerability
| Bugtraq ID: | 51 |
| Class: | Unknown |
| CVE: |
CVE-1999-1395 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 22 1992 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | |
| Vulnerable: |
Digital VMS 5.4.2 Digital VMS 5.4.1 Digital VMS 5.4 Digital VMS 5.3.2 Digital VMS 5.3.1 Digital VMS 5.3 Digital VMS 5.2.1 Digital VMS 5.2 Digital VMS 5.1.2 Digital VMS 5.1.1 Digital VMS 5.1 B Digital VMS 5.1 Digital VMS 5.0.2 Digital VMS 5.0.1 Digital VMS 5.0 |
| Not Vulnerable: |
Digital VMS 5.5.1 Digital VMS 5.5 Digital VMS 5.4.3 |
Discussion
VMS Monitor Vulnerability
Unauthorized privileges may be expanded to authorized
users of a system under certain conditions, via the Monitor
utility. This problem will not permit unauthorized access
entry, as individuals attempting to gain unauthorized access
will continue to be denied through the standard VMS
security mechanisms
Unauthorized privileges may be expanded to authorized
users of a system under certain conditions, via the Monitor
utility. This problem will not permit unauthorized access
entry, as individuals attempting to gain unauthorized access
will continue to be denied through the standard VMS
security mechanisms
Exploit / POC
VMS Monitor Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
VMS Monitor Vulnerability
Solution:
This potential vulnerability does not exist in VMS V5.4-3
(released in October 1991) and later versions of VMS
through V5.5-1.
Digital strongly recommends that you upgrade to a minimum
of VMS V5.4-3, and further, to the latest release of VMS
V5.5-1. (released in July, 1992)
A VMS V5.0 through V5.4-2 remedial kit is now available
by contacting your normal Digital Services Support
organization. The kit may be identified as
MONTOR$S01_05* or CSCPAT_1047 via DSIN , and
DSNlink.
Solution:
This potential vulnerability does not exist in VMS V5.4-3
(released in October 1991) and later versions of VMS
through V5.5-1.
Digital strongly recommends that you upgrade to a minimum
of VMS V5.4-3, and further, to the latest release of VMS
V5.5-1. (released in July, 1992)
A VMS V5.0 through V5.4-2 remedial kit is now available
by contacting your normal Digital Services Support
organization. The kit may be identified as
MONTOR$S01_05* or CSCPAT_1047 via DSIN , and
DSNlink.