Veritas-bu

[Veritas-bu] NetBackup (possible root) Exploit (4.5,5.0,5.1, 6.0)!

2005-10-12 13:27:31
Subject: [Veritas-bu] NetBackup (possible root) Exploit (4.5,5.0,5.1, 6.0)!
From: scb4 AT georgetown DOT edu (Steve Beuttel)
Date: Wed, 12 Oct 2005 13:27:31 -0400
You lose GUI auth. tcpwrappers is a quick stop, until you can patch, if 
you want to use the GUI.

-Steve-
~~~~~


Mark.Donaldson AT cexp DOT com wrote:

> What's the penalty for just disabling the port in the /etc/services or 
> /etc/inetd.conf files?
>
> -----Original Message-----
> From: Piszcz, Justin [mailto:jpiszcz AT servervault DOT com]
> Sent: 12 October 2005 12:12
> To: veritas-bu AT mailman.eng.auburn DOT edu
> Subject: [Veritas-bu] NetBackup (possible root) Exploit 
> (4.5,5.0,5.1,6.0)!
>  
> Better get patching! J
>  
> Dear Valued Symantec Customer,
>  
> This is to inform you that Symantec Enterprise Technical Support has
> just issued a security alert. This is a critical technical issue for:
>  
> VERITAS NetBackup (tm) DataCenter 4.5 - including all present
> Maintenance Packs and Feature Packs
>  
> VERITAS NetBackup (tm) BusinesServer 4.5 - including all present
> Maintenance Packs and Feature Packs
>  
> VERITAS NetBackup (tm) Enterprise Server 5.0, 5.1, and 6.0 - including
> all present Maintenance Packs for each version
>  
> VERITAS NetBackup (tm) Server 5.0, 5.1, and 6.0 - including all present
> Maintenance Packs for each version
>  
> For a detailed description of this issue and our recommendations, please
> review the following reference document:
>  
> http://support.veritas.com/docs/279085
>  
> This email is for the intended addressee only.
> If you have received it in error then you must not use, retain, 
> disseminate or otherwise deal with it.
> Please notify the sender by return email.
> The views of the author may not necessarily constitute the views of 
> EADS Astrium Limited.
> Nothing in this email shall bind EADS Astrium Limited in any contract 
> or obligation.
>
> EADS Astrium Limited, Registered in England and Wales No. 2449259
> Registered Office: Gunnels Wood Road, Stevenage, Hertfordshire, SG1 
> 2AS, England
>
>
> This email is for the intended addressee only.
> If you have received it in error then you must not use, retain, 
> disseminate or otherwise deal with it.
> Please notify the sender by return email.
> The views of the author may not necessarily constitute the views of 
> EADS Astrium Limited.
> Nothing in this email shall bind EADS Astrium Limited in any contract 
> or obligation.
>
> EADS Astrium Limited, Registered in England and Wales No. 2449259
> Registered Office: Gunnels Wood Road, Stevenage, Hertfordshire, SG1 
> 2AS, England
>