The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2005-08-20T04:00:00
Updated: 2024-08-07T21:13:53.560Z
Reserved: 2005-02-11T00:00:00
Link: CVE-2005-0359
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-08-23T04:00:00.000
Modified: 2024-11-20T23:54:57.747
Link: CVE-2005-0359
Redhat
No data.