Legato NetWorker Plaintext Log File Vulnerability
BID:3842
Info
Legato NetWorker Plaintext Log File Vulnerability
| Bugtraq ID: | 3842 |
| Class: | Design Error |
| CVE: |
CVE-2002-0114 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 10 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was discovered by "Venkatesh babu Sira" <[email protected]> and submitted to BugTraq on January 10th, 2002. |
| Vulnerable: |
Legato NetWorker 6.1 |
| Not Vulnerable: | |
Discussion
Legato NetWorker Plaintext Log File Vulnerability
Legato NetWorker is a server package designed to help share data, media and backup processes across a heterogeneous network. The Legato NetWorker server will run on a number of Unix variants, as well as Microsoft Windows NT/2000 systems.
Extremely sensitive information is stored in plaintext in logs, such as authentication credentials (username/password) for systems that have been backed up. A local attacker able to peruse the contents of the log files may be able to use such information to gain access to other hosts on the network, possibly with elevated privileges.
This issue is further compounded by the fact Legato NetWorker, by default, creates log files with world-readable permissions. This additional vulnerability is described in BugTraq ID 3840 "Legato NetWorker Insecure Log Permissions Vulnerability".
This vulnerability was discovered in Legato NetWorker 6.1 and has not been confirmed with other versions. However, the possibility that other versions are affected shouldn't be ruled out.
Legato NetWorker is a server package designed to help share data, media and backup processes across a heterogeneous network. The Legato NetWorker server will run on a number of Unix variants, as well as Microsoft Windows NT/2000 systems.
Extremely sensitive information is stored in plaintext in logs, such as authentication credentials (username/password) for systems that have been backed up. A local attacker able to peruse the contents of the log files may be able to use such information to gain access to other hosts on the network, possibly with elevated privileges.
This issue is further compounded by the fact Legato NetWorker, by default, creates log files with world-readable permissions. This additional vulnerability is described in BugTraq ID 3840 "Legato NetWorker Insecure Log Permissions Vulnerability".
This vulnerability was discovered in Legato NetWorker 6.1 and has not been confirmed with other versions. However, the possibility that other versions are affected shouldn't be ruled out.
Exploit / POC
Legato NetWorker Plaintext Log File Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Legato NetWorker Plaintext Log File Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Legato NetWorker Plaintext Log File Vulnerability
References:
References: