First published: Sat Aug 20 2005(Updated: )
EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWorker | =4.2.2 | |
NetWorker | =6.0 | |
NetWorker | =6.1 | |
NetWorker | =7.2 | |
NetWorker | =7.13 | |
Sun Solstice Backup | =6.0 | |
Sun Solstice Backup | =6.1 | |
Sun Storedge Enterprise Backup Software | =7.0 | |
Sun Storedge Enterprise Backup Software | =7.1 | |
Sun Storedge Enterprise Backup Software | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0357 is considered a high severity vulnerability that allows remote authentication bypass.
To fix CVE-2005-0357, you should update or patch the affected software to a version that mitigates this vulnerability.
CVE-2005-0357 affects EMC Legato NetWorker versions 4.2.2, 6.0, 6.1, and 7.2, as well as Sun Solstice Backup versions 6.0 and 6.1.
CVE-2005-0357 exploits the AUTH_UNIX authentication method, which relies on user ID for authentication.
Yes, an attacker can gain unauthorized privileges by spoofing a username or UID due to the vulnerability in CVE-2005-0357.