A potential security vulnerability has been discovered in MultiNet, TCPware, and PMDF software that could allow a malicious user to execute arbitrary DCL commands with elevated system privileges.
This vulnerability affects MultiNet 4.1 through 4.4, TCPware v5.4 through v5.6, and PMDF v6.0 through v6.2 on OpenVMS.
Process Software is not aware of any cases in which this vulnerability has been exploited. However, we strongly recommend installing the appropriate ECO or patch kit to eliminate the vulnerability.
We apologize for any inconvenience this may cause you. If you have trouble accessing these patches, please contact customer support at (800) 394-8700 or (508) 628-5074.
MultiNet Links to Mandatory Patch Kits
- SMTP
- FTP
Note: This security vulnerability may occur in prior versions of MultiNet. Process Software strongly recommends you upgrade.
TCPware Links to Mandatory Patch Kits
PMDF on OpenVMS Links to Mandatory Patch Kits
New UA (PMDF MAIL images) to download. Once UA.ZIP has been
downloaded, unzip it to produce UA.EXE, and copy UA.EXE to PMDF_EXE:.
Then issue this command on each node in your cluster:
INSTALL REPLACE PMDF_EXE:UA.EXE
|