PT-2005-1435 · Emc+1 · Legato Portmapper+3
Publicado
2005-08-20
·
Atualizado
2017-07-11
·
CVE-2005-0359
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
EMC Legato NetWorker versions prior to the fixed version
Sun Solstice Backup versions 6.0 through 6.1
StorEdge Enterprise Backup versions 7.0 through 7.2
Description
The issue allows remote attackers to cause a denial of service or obtain sensitive information from services. This is achieved by exploiting the lack of access restriction to the
pmap set and pmap unset commands in the Legato PortMapper. Attackers can use pmap unset to un-register a service, causing a denial of service, or use pmap set to register a new service and obtain sensitive information.Recommendations
For EMC Legato NetWorker, update to a version that includes the fix for this issue.
For Sun Solstice Backup versions 6.0 through 6.1, restrict access to the
pmap set and pmap unset commands until a patch is available.
For StorEdge Enterprise Backup versions 7.0 through 7.2, consider disabling the Legato PortMapper service as a temporary workaround until a fix is applied.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Emc Legato Networker
Legato Portmapper
Storedge Enterprise Backup
Sun Solstice Backup