[Info-vax] VSI strategy for OpenVMS
Simon Clubley
clubley at remove_me.eisner.decus.org-Earth.UFP
Fri Sep 17 14:09:02 EDT 2021
On 2021-09-17, Arne Vajhøj <arne at vajhoej.dk> wrote:
>
> If they can insert and try execute x86-64 instructions then I would
> expect that the same would be possible with Alpha instructions and
> that it could work.
>
Once they have learnt the Alpha architecture and compiled a cross
assembler for Alpha. They will already know the x86-64 architecture
and have an assembler to hand.
> The vulnerability needs to get identified and fixed.
>
> Actually executing some code looks super cool as a screenshot. But
> it does not matter from a security perspective.
>
It most certainly does matter !!!!
If it's a simple crasher, any data on the system cannot be accessed
using it.
If the researchers have turned it into a RCE vulnerability, then an
attacker could have done the same against live sites and their data
could now be compromised.
Simon.
--
Simon Clubley, clubley at remove_me.eisner.decus.org-Earth.UFP
Walking destinations on a map are further away than they appear.
More information about the Info-vax
mailing list