First published: Mon Apr 30 2007(Updated: )
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Backup Exec System Recovery | =6.5 | |
Symantec Backup Exec System Recovery | =6.52 | |
Symantec Backup Exec System Recovery | =6.52a | |
Symantec Backup Exec System Recovery | =6.53 | |
Symantec System Recovery | =6.0 | |
Symantec System Recovery | =6.01 | |
Symantec System Recovery | =6.02 | |
Ghost | =10.0 | |
Ghost | =10.0 | |
Ghost | =10.0 | |
Ghost | =10.01 | |
Symantec Norton Save and Recovery | =1.01 | |
Symantec Norton Save and Recovery | =1.01b | |
Symantec Norton Save and Recovery | =11.0 | |
Symantec Norton Save and Recovery | =11.01 | |
Symantec Norton Save and Recovery | =11.01b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2361 is rated as a medium severity vulnerability due to its potential for local exploitation leading to unauthorized access.
To fix CVE-2007-2361, change the permissions of the configuration file to restrict access from unauthorized users.
CVE-2007-2361 affects various versions of Symantec products like Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery.
CVE-2007-2361 primarily allows local users to exploit the vulnerability, not through remote access.
The implications of CVE-2007-2361 include the risk of exposing sensitive network share credentials to unauthorized local users.