First published: Fri Mar 15 2002(Updated: )
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWorker | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-0113 is considered moderate due to the possibility of local users gaining unauthorized access to sensitive information.
To fix CVE-2002-0113, change the permissions of the log files in the /nsr/logs/ directory to restrict world-readable access.
CVE-2002-0113 affects EMC NetWorker versions prior to 7.0, specifically version 6.1.
CVE-2002-0113 is a local information disclosure vulnerability due to improperly configured file permissions.
Yes, CVE-2002-0113 can potentially lead to privilege escalation by allowing local users to access sensitive information.