EMC Legato Networker Multiple Vulnerabilities
BID:14582
Info
EMC Legato Networker Multiple Vulnerabilities
| Bugtraq ID: | 14582 |
| Class: | Unknown |
| CVE: |
CVE-2005-0357 CVE-2005-0358 CVE-2005-0359 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | NOAA NCIRT Lab reported this vulnerability. |
| Vulnerable: |
Sun StorEdge Enterprise Backup Software 7.2 L Sun StorEdge Enterprise Backup Software 7.2 _x86 Sun StorEdge Enterprise Backup Software 7.2 Sun StorEdge Enterprise Backup Software 7.1 L Sun StorEdge Enterprise Backup Software 7.1 _x86 Sun StorEdge Enterprise Backup Software 7.1 Sun StorEdge Enterprise Backup Software 7.0 _x86 Sun StorEdge Enterprise Backup Software 7.0 Sun Solstice Backup Software 6.1 _x86 Sun Solstice Backup Software 6.1 Sun Solstice Backup Software 6.0 _x86 Sun Solstice Backup Software 6.0 EMC Legato Networker 7.2 EMC Legato Networker 7.1.3 EMC Legato Networker 6.0 x |
| Not Vulnerable: | |
Discussion
EMC Legato Networker Multiple Vulnerabilities
EMC Legato Networker is affected by multiple denial of service, privilege escalation, unauthorized access and arbitrary command execution vulnerabilities.
Several vulnerabilities affect EMC Legato Networker which can be exploited to cause denial of service, privilege escalation, unauthorized access and information disclosure.
EMC Legato Networker is affected by multiple denial of service, privilege escalation, unauthorized access and arbitrary command execution vulnerabilities.
Several vulnerabilities affect EMC Legato Networker which can be exploited to cause denial of service, privilege escalation, unauthorized access and information disclosure.
Exploit / POC
EMC Legato Networker Multiple Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EMC Legato Networker Multiple Vulnerabilities
Solution:
EMC has released patches addressing these issues.
Sun Microsystems have released an advisory regarding these issues. Users are advised to contact Sun regarding the availability of patches and updates.
Sun has released an updated advisory (101886) to address these issues in affected products. Please see the referenced advisory for more information. Customers are advised to contact Sun to obtain patches specified in the advisory.
EMC Legato Networker 7.1.3
EMC Legato Networker 7.2
Solution:
EMC has released patches addressing these issues.
Sun Microsystems have released an advisory regarding these issues. Users are advised to contact Sun regarding the availability of patches and updates.
Sun has released an updated advisory (101886) to address these issues in affected products. Please see the referenced advisory for more information. Customers are advised to contact Sun to obtain patches specified in the advisory.
EMC Legato Networker 7.1.3
-
EMC networker_security_hotfix.htm
http://www.legato.com/support/websupport/patches_updates/networker_sec urity_hotfix.htm
EMC Legato Networker 7.2
-
EMC networker_security_hotfix.htm
http://www.legato.com/support/websupport/patches_updates/networker_sec urity_hotfix.htm
References
EMC Legato Networker Multiple Vulnerabilities
References:
References:
- EMC Legato Networker Product Alert (EMC)
- Sun Alert ID: 101886 (Sun)
- VU#407641 - EMC Legato NetWorker database services use insufficient authenticati (US-CERT)
- VU#606857 - EMC Legato NetWorker uses weak AUTH_UNIX authentication (US-CERT)
- VU#801089 - EMC Legato NetWorker portmapper allows remote calls to "pmap_set" an (US-CERT)