PT-2007-3694 · Symantec · Norton Ghost+3

Published

2007-04-30

·

Updated

2017-07-29

·

CVE-2007-2361

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Symantec Norton Ghost versions prior to 20070426 Symantec Norton Save & Recovery versions prior to 20070426 Symantec LiveState Recovery versions prior to 20070426 Symantec BackupExec System Recovery versions prior to 20070426
Description The issue concerns the use of weak permissions for a configuration file that stores network share credentials. When remote backups of restore points images are configured, this file becomes world-readable, allowing local users to obtain the credentials by simply reading the file. This could potentially lead to unauthorized access to sensitive data.
Recommendations For Symantec Norton Ghost versions prior to 20070426, update to a version released after 20070426 to ensure the configuration file is properly secured. For Symantec Norton Save & Recovery versions prior to 20070426, update to a version released after 20070426 to ensure the configuration file is properly secured. For Symantec LiveState Recovery versions prior to 20070426, update to a version released after 20070426 to ensure the configuration file is properly secured. For Symantec BackupExec System Recovery versions prior to 20070426, update to a version released after 20070426 to ensure the configuration file is properly secured.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2361

Affected Products

Backupexec System Recovery
Livestate Recovery
Norton Ghost
Norton Save & Recovery