[Info-vax] VSI strategy for OpenVMS

Simon Clubley clubley at remove_me.eisner.decus.org-Earth.UFP
Fri Sep 17 14:09:02 EDT 2021


On 2021-09-17, Arne Vajhøj <arne at vajhoej.dk> wrote:
>
> If they can insert and try execute x86-64 instructions then I would
> expect that the same would be possible with Alpha instructions and
> that it could work.
>

Once they have learnt the Alpha architecture and compiled a cross
assembler for Alpha. They will already know the x86-64 architecture
and have an assembler to hand.

> The vulnerability needs to get identified and fixed.
>
> Actually executing some code looks super cool as a screenshot. But
> it does not matter from a security perspective.
>

It most certainly does matter !!!!

If it's a simple crasher, any data on the system cannot be accessed
using it.

If the researchers have turned it into a RCE vulnerability, then an
attacker could have done the same against live sites and their data
could now be compromised.

Simon.

-- 
Simon Clubley, clubley at remove_me.eisner.decus.org-Earth.UFP
Walking destinations on a map are further away than they appear.



More information about the Info-vax mailing list