|
Hitachi Multiple Hibun Products Security Restriction Bypass
|
|
Secunia Advisory:
|
SA15863
|
|
|
Release Date:
|
2005-06-30
|
|
Popularity:
|
5,413 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Security Bypass
|
|
Where:
|
Local system
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | Hibun Advanced Edition Server 6.x Hibun Advanced Edition Server 7.x Hibun Advanced Information Cypher 6.x Hibun Advanced Information Cypher 7.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: Two security issues have been reported in various Hitachi Hibun products, which can be exploit by malicious, local users to bypass certain security restrictions.
1) An error causes PCMCIA hard disks that are attached to a system to be incorrectly treated as internal hard disks. As a result, Hibun is unable to restrict files that are copied out to the hard disks.
2) An error in the Hibun Viewer allows the user to have privileges beyond the View function when using the viewer from a client PC.
See the vendor advisory for a matrix of affected versions.
Solution: Hibun Advanced Edition Server (versions 07-50 through 07-50-/B):
Update to version 7.50/C
Hibun Advanced Edition Information Cypher (versions 07-50 through 07-50-/B):
Update to version 7.50/C
Updates are reportedly being scheduled for the other versions.
Provided and/or discovered by: Reported by vendor.
Original Advisory: Hitachi:
http://www.hitachi-support.com/security_e/vuls_e/HS05-010_e/index-e.html
http://www.hitachi-support.com/security_e/vuls_e/HS05-011_e/index-e.html
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|