Veritas Cluster Server远程root用户访问漏洞

漏洞信息详情

Veritas Cluster Server远程root用户访问漏洞

漏洞简介

Veritas Cluster服务程序是一款存储控制解决方案。
运行在Unix/Linux系统上的Veritas Cluster服务程序存在一个未明问题,远程攻击者可以利用这个漏洞以root用户权限访问系统。
目前没有提供详细漏洞细节。其中Solaris、HP-UX、AIX和Linux系统受此漏洞影响,不过Veritas Cluster Server for Windows系统不受此漏洞影响。

漏洞公告

厂商补丁:
Veritas
——-
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

Veritas Software Cluster Server 1.3 Solaris:

Veritas Software Patch vcs.130-patch03_239344.tar.Z

http://ftp.support.veritas.com/pub/support/products/” target=”_blank”>
http://ftp.support.veritas.com/pub/support/products/

ClusterServer_UNIX/vcs.130-patch03_239344.tar.Z

Veritas Software Cluster Server 2.2 MP2:

Veritas Software Patch

vcs.2.2_MP2_i147547a.rhel_21_i686.tar_270095.gz

http://seer.support.veritas.com/docs/270095.htm” target=”_blank”>
http://seer.support.veritas.com/docs/270095.htm

Veritas Software Patch

vcs.2.2_MP2_i147547a.rhel_30_i686.tar_270096.gz

http://seer.support.veritas.com/docs/270096.htm” target=”_blank”>
http://seer.support.veritas.com/docs/270096.htm

Veritas Software Patch

vcs.2.2_MP2_i147547a.rhel_30_u2_ia64.tar_270097.gz

http://seer.support.veritas.com/docs/270097.htm” target=”_blank”>
http://seer.support.veritas.com/docs/270097.htm

Veritas Software Patch

vcs.2.2_MP2_i147547a.sles8_sp3_i686.tar_270092.gz

http://seer.support.veritas.com/docs/270092.htm” target=”_blank”>
http://seer.support.veritas.com/docs/270092.htm

Veritas Software Patch

vcs.2.2_MP2_i147547a.esx_210_i686.tar_271277.gz

http://seer.support.veritas.com/docs/271277.htm” target=”_blank”>
http://seer.support.veritas.com/docs/271277.htm

Veritas Software Cluster Server 3.5 Solaris MP3:

Veritas Software Patch vcs.3.5P3+i147547a.sol_270071.tar.Z

http://seer.support.veritas.com/docs/270071.htm” target=”_blank”>
http://seer.support.veritas.com/docs/270071.htm

Veritas Software Cluster Server 3.5 MP1:

Veritas Software Patch vcs.3.5P1+i147547b.aix_270090.tar.Z

http://seer.support.veritas.com/docs/270090.htm” target=”_blank”>
http://seer.support.veritas.com/docs/270090.htm

Veritas Software Cluster Server 3.5 HP-UX Update 2:

Veritas Software Patch vcs.3.5P1+i147547b.hp_270074.tar.Z

http://seer.support.veritas.com/docs/270074.htm” target=”_blank”>
http://seer.support.veritas.com/docs/270074.htm

参考网址

来源: XF
名称: vcs-gain-unauth-access(17719)
链接:http://xforce.iss.net/xforce/xfdb/17719

来源: BID
名称: 11421
链接:http://www.securityfocus.com/bid/11421

来源: OSVDB
名称: 10757
链接:http://www.osvdb.org/10757

来源: seer.support.veritas.com
链接:http://seer.support.veritas.com/docs/271040.htm

来源: SECUNIA
名称: 12833
链接:http://secunia.com/advisories/12833

来源: SECTRACK
名称: 1011693
链接:http://securitytracker.com/id?1011693

来源:NSFOCUS
名称:7025
链接:http://www.nsfocus.net/vulndb/7025

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享