CVE-2005-0359
Last modified
CVE-2005-0359 is a vulnerability of currently unknown severity. The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.. EPSS estimates a 4.29% chance of exploitation in the next 30 days.
Description
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Legato Networker | 4.2.2 |
| Emc | Legato Networker | 6.0 |
| Emc | Legato Networker | 6.1 |
| Emc | Legato Networker | 7.2 |
| Emc | Legato Networker | 7.13 |
| Sun | Solstice Backup | 6.0 |
| Sun | Solstice Backup | 6.1 |
| Sun | Storedge Enterprise Backup Software | 7.0 |
| Sun | Storedge Enterprise Backup Software | 7.1 |
| Sun | Storedge Enterprise Backup Software | 7.2 |
References
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/801089Patch, Third Party Advisory, US Government Resource
- http://secunia.com/advisories/16464Patch, Vendor Advisory
- http://secunia.com/advisories/16470Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/801089Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0359?
How severe is CVE-2005-0359?
How do I fix CVE-2005-0359?
Are you affected by CVE-2005-0359?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
