First published: Mon Jun 04 2007(Updated: )
The Pascal run-time library (PAS$RTL.EXE) before 20070418 on OpenVMS for Integrity Servers 8.3, and PAS$RTL.EXE before 20070419 on OpenVMS Alpha 8.3, does not properly restore PC and PSL values, which allows local users to cause a denial of service (system crash) via certain Pascal code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenVMS | =8.3 | |
OpenVMS | =8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2998 has a medium severity level as it can lead to a denial of service via system crash.
To fix CVE-2007-2998, update the Pascal run-time library (PAS$RTL.EXE) to version 20070418 or later for Integrity Servers, or version 20070419 or later for Alpha.
CVE-2007-2998 affects users of OpenVMS version 8.3 on both Integrity Servers and Alpha systems.
CVE-2007-2998 exploits a flaw in the Pascal run-time library that fails to properly restore PC and PSL values.
Currently, there are no published workarounds for CVE-2007-2998 other than applying the appropriate updates.