EMC Legato Networker 权限提升漏洞

漏洞信息详情

EMC Legato Networker 权限提升漏洞

漏洞简介

EMC Legato NetWorker,Solstice Backup 6.0和6.1及StorEdge Enterprise Backup 6.0至7.2不能正确地验证认证标识符。这使得远程攻击者可以通过修改认证标识符获取权限。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

EMC Legato Networker 7.1.3

EMC networker_security_hotfix.htm

http://www.legato.com/support/websupport/patches_updates/networker_security_hotfix.htm

EMC Legato Networker 7.2

EMC networker_security_hotfix.htm

http://www.legato.com/support/websupport/patches_updates/networker_security_hotfix.htm

参考网址

来源: US-CERT

名称: VU#407641

链接:http://www.kb.cert.org/vuls/id/407641

来源: XF

名称: legato-token-gain-privileges(21892)

链接:http://xforce.iss.net/xforce/xfdb/21892

来源: BID

名称: 14582

链接:http://www.securityfocus.com/bid/14582

来源: SUNALERT

名称: 101886

链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1

来源: SECTRACK

名称: 1014713

链接:http://securitytracker.com/id?1014713

来源: SECUNIA

名称: 16464

链接:http://secunia.com/advisories/16464

来源: OSVDB

名称: 18801

链接:http://www.osvdb.org/18801

来源: www.legato.com

链接:http://www.legato.com/support/websupport/product_alerts/081605_NW_token_authentication.htm

来源: SECUNIA

名称: 16470

链接:http://secunia.com/advisories/16470

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享