4.6
CVSSv2

CVE-2002-1513

Published: 02/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The UCX POP server in HP TCP/IP services for OpenVMS 4.2 up to and including 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

compaq tcp-ip services 4.2

compaq tcp-ip services 5.0a

compaq tcp-ip services 5.1

compaq tcp-ip services 5.3

Exploits

source: wwwsecurityfocuscom/bid/5790/info An issue with the UCX POP (Post Office Protocol) server used by OpenVMS has been reported It is possible for a malicous local user to overwrite arbitrary files on the filesystem by exploiting a vulnerability in the UCX POP server $ $ break_it :== $sys$system:ucx$pop_serverexe $ break_it -logfi ...