Description
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.
Affected products
- EMC / legato_networker4.2.2 – 4.2.2
- EMC / legato_networker6.0 – 6.0
- EMC / legato_networker6.1 – 6.1
- EMC / legato_networker7.2 – 7.2
- EMC / legato_networker7.13 – 7.13
- sun / solstice_backup6.0 – 6.0
- sun / solstice_backup6.1 – 6.1
- sun / storedge_enterprise_backup_software7.0 – 7.0
- sun / storedge_enterprise_backup_software7.1 – 7.1
- sun / storedge_enterprise_backup_software7.2 – 7.2
References
- MISChttp://www.kb.cert.org/vuls/id/801089
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/21893
- VENDOR_ADVISORYhttp://secunia.com/advisories/16470
- VENDOR_ADVISORYhttp://secunia.com/advisories/16464
- MISChttp://securitytracker.com/id?1014713
- MISChttp://www.securityfocus.com/bid/14582
- MISChttp://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htm
- MISChttp://www.osvdb.org/18802
- MISChttp://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1