Sujet : Re: Was Itanium a safer architecture ?
De : arne (at) *nospam* vajhoej.dk (Arne Vajhøj)
Groupes : comp.os.vmsDate : 01. Jun 2026, 23:58:27
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <10vl2qj$2i6gp$1@dont-email.me>
References : 1 2 3 4 5 6
User-Agent : Mozilla Thunderbird
On 6/1/2026 5:08 PM, Arne Vajhøj wrote:
On 6/1/2026 3:15 PM, Simon Clubley wrote:
It's an 8.5 Arne. :-) That's not a process crash. That's a confirmed
exploitable vulnerability. (At least on Alpha/x86-64).
You can speculate about Itanium being different. But I have not
seen anything in what VSI has published that indicate Itanium is
different from this one.
Which is not true.
The VSI CVE page actually say they are different and do explain
more about the problem:
<quote>
An issue was discovered in OpenVMS V8.4 through V8.4-2L2 on Alpha, V8.4 through V8.4-2L3 on IA64, and through V9.2-3 on x86. Passing a long string value to the F$CUNITS lexical function may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on Alpha and x86 and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, or HP.
</quote>
Arne
Haut de la page
Les messages affichés proviennent d'usenet.
NewsPortal