NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by reading the file.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://securitytracker.com/id?1017472 | vdb entry |
http://www.securityfocus.com/bid/19783 | patch vdb entry |
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V7.3-2/AXP_DNVOSIECO03-V732.txt | |
http://www.osvdb.org/28272 | vdb entry |
http://secunia.com/advisories/21705 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/28695 | vdb entry |
http://secunia.com/advisories/23632 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2006/3423 | vdb entry vendor advisory |
http://securitytracker.com/id?1016772 | vdb entry |
ftp://ftp.itrc.hp.com/openvms_patches/alpha/V8.2/AXP_DNVOSIECO02-V82.txt |