First published: Fri Sep 05 2008(Updated: )
The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenVMS | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3946 is considered a low severity vulnerability that allows local users to read arbitrary files.
To fix CVE-2008-3946, ensure that permissions for .plan and .project files are restricted to prevent unauthorized access.
CVE-2008-3946 affects local users of HP TCP/IP Services for OpenVMS version 5.x.
CVE-2008-3946 allows unauthorized access to local .plan and .project files.
No, CVE-2008-3946 is a local vulnerability that requires local user access to exploit.