Veritas NetBackup bpcd任意命令执行漏洞(CVE-2015-6550)
发布日期:2016-05-07
更新日期:2016-05-09
受影响系统:
Veritas Backup Exec 7.7.x < 7.7.2
Veritas Backup Exec 7.6.1.x - 7.6.1.2
Veritas Backup Exec 7.6.0.x - 7.6.0.4
Veritas NetBackup Appliance <= 2.5.4
Veritas NetBackup Appliance 2.7.x < 2.7.2
Veritas NetBackup Appliance 2.6.1.x <= 2.6.1.2
Veritas NetBackup Appliance 2.6.0.x <= 2.6.0.4
描述:
CVE(CAN) ID: CVE-2015-6550
Veritas Backup Exec是数据保护和系统恢复解决方案。
Veritas NetBackup 7.x - 7.5.0.7, 7.6.0.x - 7.6.0.4, 7.6.1.x - 7.6.1.2, 7.7.x < 7.7.2, NetBackup Appliance <= 2.5.4, 2.6.0.x <= 2.6.0.4, 2.6.1.x <= 2.6.1.2, 2.7.x < 2.7.2版本, bpcd存在安全漏洞, 远程攻击者通过构造的输入, 可执行任意命令。
<*来源:Emilien Girault
*>
建议:
厂商补丁:
Veritas
-------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
https://www.veritas.com/content/support/en_US/security/VTS16-001.html