Executive brief
A vulnerability in the dxconsole utility of the DEC OSF/1 operating system allows local users to read sensitive files they should not have access to. By exploiting this flaw, an attacker with a standard user account could view system configuration files or private data, potentially leading to further unauthorized access or data theft. This affects older versions of the DEC OSF/1 operating system.
Technical details
The dxconsole utility in DEC OSF/1 version 3.2C and earlier contains an arbitrary file read vulnerability. A local attacker can exploit this by using the '-file' command-line parameter to specify a file that the user would normally not have permissions to view. Because the utility does not properly restrict file access based on the user's privileges, it can be used to disclose sensitive system or user information. This is a local vulnerability requiring shell access to the affected system. Patch information is referenced in historical vendor bulletins from DEC and CERT.
Affected products
- DEC OSF/1 3.2C and earlier
Timeline
- 1996-04-03: disclosed