First published: Fri Sep 05 2008(Updated: )
Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenVMS | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3940 has been classified as a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
The recommended fix for CVE-2008-3940 is to update to a patched version of HP TCP/IP Services for OpenVMS that addresses this format string vulnerability.
Local users of HP TCP/IP Services for OpenVMS version 5.x are affected by CVE-2008-3940.
CVE-2008-3940 is a format string vulnerability that can be exploited through specific user files.
The vulnerability in CVE-2008-3940 involves exploits in the user's .plan and .project files.