PT-2005-1435 · Emc+1 · Legato Portmapper+3

Publicado

2005-08-20

·

Atualizado

2017-07-11

·

CVE-2005-0359

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions EMC Legato NetWorker versions prior to the fixed version Sun Solstice Backup versions 6.0 through 6.1 StorEdge Enterprise Backup versions 7.0 through 7.2
Description The issue allows remote attackers to cause a denial of service or obtain sensitive information from services. This is achieved by exploiting the lack of access restriction to the pmap set and pmap unset commands in the Legato PortMapper. Attackers can use pmap unset to un-register a service, causing a denial of service, or use pmap set to register a new service and obtain sensitive information.
Recommendations For EMC Legato NetWorker, update to a version that includes the fix for this issue. For Sun Solstice Backup versions 6.0 through 6.1, restrict access to the pmap set and pmap unset commands until a patch is available. For StorEdge Enterprise Backup versions 7.0 through 7.2, consider disabling the Legato PortMapper service as a temporary workaround until a fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0359

Produtos afetados

Emc Legato Networker
Legato Portmapper
Storedge Enterprise Backup
Sun Solstice Backup