Hitachi Multiple Hibun Products Security Restriction Bypass
Secunia Advisory: SA15863
Release Date: 2005-06-30
Popularity: 5,413 views

Critical:
Less critical
Impact: Security Bypass
Where: Local system
Solution Status: Partial Fix

Software:Hibun Advanced Edition Server 6.x
Hibun Advanced Edition Server 7.x
Hibun Advanced Information Cypher 6.x
Hibun Advanced Information Cypher 7.x

Subscribe: Instant alerts on relevant vulnerabilities


Description:
Two security issues have been reported in various Hitachi Hibun products, which can be exploit by malicious, local users to bypass certain security restrictions.

1) An error causes PCMCIA hard disks that are attached to a system to be incorrectly treated as internal hard disks. As a result, Hibun is unable to restrict files that are copied out to the hard disks.

2) An error in the Hibun Viewer allows the user to have privileges beyond the View function when using the viewer from a client PC.

See the vendor advisory for a matrix of affected versions.

Solution:
Hibun Advanced Edition Server (versions 07-50 through 07-50-/B):
Update to version 7.50/C

Hibun Advanced Edition Information Cypher (versions 07-50 through 07-50-/B):
Update to version 7.50/C

Updates are reportedly being scheduled for the other versions.

Provided and/or discovered by:
Reported by vendor.

Original Advisory:
Hitachi:
http://www.hitachi-support.com/security_e/vuls_e/HS05-010_e/index-e.html
http://www.hitachi-support.com/security_e/vuls_e/HS05-011_e/index-e.html


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB Multiple Vulnerabilities // 67 views
2. Microsoft Word Malformed Object Pointer Vulnerability // 32 views
3. Zeroboard Multiple Vulnerabilities // 29 views
4. Zeroboard Two Vulnerabilities // 26 views
5. Cisco ASA and PIX Security Appliances Multiple Vulnerabilities // 25 views
6. Adobe Flash Player Multiple Vulnerabilities // 24 views
7. ELinks "smb" Protocol File Upload/Download Vulnerability // 23 views
8. 3Com Wireless 8760 Access Point HTTP Request Processing Denial of Service // 21 views
9. HP OpenView Select Identity Connectors Information Disclosure // 20 views
10. Opera Multiple Vulnerabilities // 20 views