EMC Avamar Backup Client Insecure File Permissions Vulnerability
BID:57005
Info
EMC Avamar Backup Client Insecure File Permissions Vulnerability
| Bugtraq ID: | 57005 |
| Class: | Design Error |
| CVE: |
CVE-2012-2291 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 19 2012 12:00AM |
| Updated: | Jun 28 2013 12:20PM |
| Credit: | EMC |
| Vulnerable: |
EMC Avamar 5.0.3 EMC Avamar 5.0.2 EMC Avamar 4.1.2 EMC Avamar 5.0.4-26 EMC Avamar 5.0.4 EMC Avamar 5.0.3-29 EMC Avamar 5.0.2-41 EMC Avamar 5.0.1-32 EMC Avamar 5.0.1 EMC Avamar 5.0.0-407 EMC Avamar 5.0 SP1 EMC Avamar 5.0 EMC Avamar 4.1.2-33 EMC Avamar 4.1.1-340 EMC Avamar 4.1.1 EMC Avamar 4.1.0-1470 EMC Avamar 4.1 |
| Not Vulnerable: | |
Discussion
EMC Avamar Backup Client Insecure File Permissions Vulnerability
EMC Avamar backup client is prone to an insecure file-permissions vulnerability.
A local attacker can exploit this issue to gain escalated privileges. This may aid in further attacks.
The following versions are affected:
EMC Avamar version 4.x
EMC Avamar version 5.x
EMC Avamar version 6.x
EMC Avamar backup client is prone to an insecure file-permissions vulnerability.
A local attacker can exploit this issue to gain escalated privileges. This may aid in further attacks.
The following versions are affected:
EMC Avamar version 4.x
EMC Avamar version 5.x
EMC Avamar version 6.x
Exploit / POC
EMC Avamar Backup Client Insecure File Permissions Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
EMC Avamar Backup Client Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.