EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions for cache directories, which allows local users to gain privileges via an unspecified symlink attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Avamar | Emc | 4.0 (including) | 4.0 (including) |
Avamar | Emc | 4.1 (including) | 4.1 (including) |
Avamar | Emc | 5.0 (including) | 5.0 (including) |
Avamar | Emc | 5.0-sp1 (including) | 5.0-sp1 (including) |
Avamar | Emc | 5.0-sp2 (including) | 5.0-sp2 (including) |
Avamar | Emc | 5.0.0-407 (including) | 5.0.0-407 (including) |
Avamar | Emc | 5.0.4-26 (including) | 5.0.4-26 (including) |
Avamar | Emc | 6.0 (including) | 6.0 (including) |