Back to search
CVE-2005-0359
Published: Aug 20, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2) obtain sensitive information from NetWorker services by using pmap_set to register a new service.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
VU#801089
third-party-advisory
x_refsource_CERT-VN
legato-portmapper-obtain-information(21893)
vdb-entry
x_refsource_XF
16470
third-party-advisory
x_refsource_SECUNIA
16464
third-party-advisory
x_refsource_SECUNIA
1014713
vdb-entry
x_refsource_SECTRACK
14582
vdb-entry
x_refsource_BID
18802
vdb-entry
x_refsource_OSVDB
101886
vendor-advisory
x_refsource_SUNALERT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now