The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via the -logfile command line option, which overrides file system permissions because the server runs with the SYSPRV and BYPASS privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tcp-ip_services | Compaq | 4.2 (including) | 4.2 (including) |
Tcp-ip_services | Compaq | 5.0a (including) | 5.0a (including) |
Tcp-ip_services | Compaq | 5.1 (including) | 5.1 (including) |
Tcp-ip_services | Compaq | 5.3 (including) | 5.3 (including) |