SB2012042001 - Multiple vulnerabilities in OpenVMS



SB2012042001 - Multiple vulnerabilities in OpenVMS

Published: April 20, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012042001
Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 25% Medium 50% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Configuration (CVE-ID: CVE-2012-3276)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows local users to cause a denial of service via unspecified vectors.


2) Input validation error (CVE-ID: CVE-2012-3277)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows remote attackers to cause a denial of service via unspecified vectors.


3) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-2010)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.


4) Input validation error (CVE-ID: CVE-2012-0134)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a denial of service via unknown vectors.


Remediation

Install update from vendor's website.