CVE-2007-2998: Medium severity OpenVMS vulnerability
The Pascal run-time library (PAS$RTL.EXE) before 20070418 on OpenVMS for Integrity Servers 8.3, and PAS$RTL.EXE before 20070419 on OpenVMS Alpha 8.3, does not properly restore PC and PSL values, which allows local users to cause a denial of service (system crash) via certain Pascal code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2998?
CVE-2007-2998 has a medium severity level as it can lead to a denial of service via system crash.
How do I fix CVE-2007-2998?
To fix CVE-2007-2998, update the Pascal run-time library (PAS$RTL.EXE) to version 20070418 or later for Integrity Servers, or version 20070419 or later for Alpha.
Who is affected by CVE-2007-2998?
CVE-2007-2998 affects users of OpenVMS version 8.3 on both Integrity Servers and Alpha systems.
What does CVE-2007-2998 exploit?
CVE-2007-2998 exploits a flaw in the Pascal run-time library that fails to properly restore PC and PSL values.
Are there known workarounds for CVE-2007-2998?
Currently, there are no published workarounds for CVE-2007-2998 other than applying the appropriate updates.