Symantec Backup Exec CVE-2013-4677 Local Insecure File Permissions Vulnerability
BID:61487
Info
Symantec Backup Exec CVE-2013-4677 Local Insecure File Permissions Vulnerability
| Bugtraq ID: | 61487 |
| Class: | Design Error |
| CVE: |
CVE-2013-4677 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 01 2013 12:00AM |
| Updated: | Oct 16 2013 12:54AM |
| Credit: | Perran Hill, Shaun Jones, Edward Torkington, Daniele Costa, and Andy Davis with NCC Group |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Symantec Backup Exec CVE-2013-4677 Local Insecure File Permissions Vulnerability
Symantec Backup Exec is prone to a local insecure-file-permissions vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may lead to unauthorized access or elevated privileges on network systems.
Symantec Backup Exec is prone to a local insecure-file-permissions vulnerability.
A local attacker can exploit this issue to obtain sensitive information that may lead to unauthorized access or elevated privileges on network systems.
Exploit / POC
Symantec Backup Exec CVE-2013-4677 Local Insecure File Permissions Vulnerability
An attacker can use readily available command-line utilities to exploit this issue.
An attacker can use readily available command-line utilities to exploit this issue.
Solution / Fix
Symantec Backup Exec CVE-2013-4677 Local Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Symantec Backup Exec CVE-2013-4677 Local Insecure File Permissions Vulnerability
References:
References:
- Symantec Backup Exec Homepage (Symantec )