Convex Storage Manager Vulnerability
BID:56
Info
Convex Storage Manager Vulnerability
| Bugtraq ID: | 56 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 16 1992 12:00AM |
| Updated: | Dec 16 1992 12:00AM |
| Credit: | |
| Vulnerable: |
Convex Storage Manager 1.0 |
| Not Vulnerable: |
Convex Storage Manager 1.0.1 |
Discussion
Convex Storage Manager Vulnerability
The "migmgr" command in CONVEX CSM contains a
security vulnerability, in ConvexOS version V10.1 of
systems that have installed the CSM facility. This
vulnerability will be fixed in the next CSM release.
Local users can gain unauthorized root access.
The "migmgr" command in CONVEX CSM contains a
security vulnerability, in ConvexOS version V10.1 of
systems that have installed the CSM facility. This
vulnerability will be fixed in the next CSM release.
Local users can gain unauthorized root access.
Exploit / POC
Convex Storage Manager Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Convex Storage Manager Vulnerability
Solution:
As root, rename the existing version of /usr/csm/bin/migmgr
and modify the permission (from 4755 to 700) to prevent
misuse.
# /bin/mv /usr/csm/bin/migmgr /usr/csm/bin/migmgr.orig
# /bin/chmod 700 /usr/csm/bin/migmgr.orig
Next, obtain and install CONVEX CSM V1.0.1 - Part No.
710-011315-003
Solution:
As root, rename the existing version of /usr/csm/bin/migmgr
and modify the permission (from 4755 to 700) to prevent
misuse.
# /bin/mv /usr/csm/bin/migmgr /usr/csm/bin/migmgr.orig
# /bin/chmod 700 /usr/csm/bin/migmgr.orig
Next, obtain and install CONVEX CSM V1.0.1 - Part No.
710-011315-003
References
Convex Storage Manager Vulnerability
References:
References: