Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Legato NetWorker不安全的日志文件许可权限漏洞
Vulnerability Description
Legato NetWorker是一个服务器软件包,用来在异种网络之间共享数据、媒体并进行备份。Legato NetWorker可运行一些UNIX变种和Windows NT/2000平台。 Legato NetWorker存在设计问题,可以使本地攻击者访问到一些敏感信息,比如用户名和口令。 nsrd是提供Legato存储管理的守护进程,它也负责启动其他守护进程。nsrd的日志文件位于/nsr/logs/目录。默认情况下nsrd以全局可读的许可权限创建日志文件供任何人读取。如果管理员试图重新定位或者删除日志
CVSS Information
N/A
Vulnerability Type
N/A