SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#801089

EMC Legato NetWorker portmapper allows remote calls to "pmap_set" and "pmap_unset"

Overview

The EMC Legato NetWorker PortMapper allows remote access to pmap_set and pmap_unset. This could allow a remote attacker to cause a denial of service or potentially to eavesdrop on communications between NetWorker programs.

I. Description

EMC Legato NetWorker is a cross-platform backup and recovery application. It is also repackaged by Sun Microsystems as Solstice Backup and StorEdge Enterprise Backup, by FSC as Fujitsu Siemens Computers' NetWorker, by NEC as WebSAM NetWorker Powered by Legato, and by Fujitsu as NetWorker.

Legato PortMapper

The Legato PortMapper, also known as lgtomapper, is a service that listens on port 7938 and converts RPC program numbers into TCP or UDP protocol port numbers. The RPC pmap_set command can be used to map a remote procedure call to a port. pmap_unset destroys the mappings between a remote procedure call and a port.

The problem

With most portmapper implementations, the pmap_set and pmap_unset calls are restricted in ways such as only allowing connections from localhost. The Legato PortMapper allows any host to call pmap_set and pmap_unset. This may allow a remote, unauthenticated attacker to unregister existing NetWorker RPC services or register new RPC services.

II. Impact

A remote unauthenticated attacker may be able to create a denial-of-service condition by unregistering NetWorker services. An attacker may be able to eavesdrop on NetWorker process communications by registering a new RPC service.

III. Solution

Apply a patch or upgrade

Apply a patch or upgrade, as specified in the EMC Legato Technical Product Alert.

Sun Solstice Backup and StorEdge Enterprise Backup customers should see Sun Alert 101866 for patch availability.

Restrict Access

You may wish to block access to the vulnerable software from outside your network perimeter, specifically by blocking access to the ports used by NetWorker (typically TCP and UDP ports 7937-9936). This will limit your exposure to attacks. However, blocking at the network perimeter would still allow attackers within the perimeter of your network to exploit the vulnerability. The use of host-based firewalls in addition to network-based firewalls can help restrict access to specific hosts within the network. It is important to understand your network's configuration and service requirements before deciding what changes are appropriate.

Systems Affected

VendorStatusDate NotifiedDate Updated
EMC SoftwareVulnerable16-Aug-2005
Fujitsu LimitedVulnerable24-Aug-2005
NECVulnerable24-Aug-2005
Sun Microsystems, Inc.Vulnerable19-Sep-2005

References


http://www.legato.com/support/websupport/product_alerts/081605_NW-7x.htm
http://www.legato.com/support/websupport/product_alerts/081605_NW_port_mapper.htm
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101886-1
http://www.legato.com/products/networker/
http://www.legato.com/support/websupport/tech_bulletins/?includefile=388.html#portmapper
http://secunia.com/advisories/16464/
http://secunia.com/advisories/16470/
http://www.securiteam.com/exploits/3E5Q3S0N5K.html
http://www.tldp.org/HOWTO/NIS-HOWTO/portmapper.html
http://www.cnn.com/2005/TECH/internet/07/25/hackers.backup.software.reut/index.html

Credit

Thanks to the NOAA NCIRT Lab for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

Date Public:2005-08-16
Date First Published:2005-08-16
Date Last Updated:2005-09-19
CERT Advisory: 
CVE-ID(s):CAN-2005-0359
NVD-ID(s):CAN-2005-0359
US-CERT Technical Alerts: 
Metric:3.66
Document Revision:29

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader