Symantec VERITAS Cluster Server (VCS) allows unauthorized root access
| vcs-gain-unauth-access (17719) |
Description:
VERITAS Cluster Server (VCS), developed by VERITAS, is used in cluster environments for Windows and Unix-based operating systems. VERITAS Cluster Server versions 2.x, 3.x and 4.x running on Solaris, HP-UX, AIX, and Linux platforms could allow a remote attacker to gain unauthorized root access on the vulnerable system.
Consequences:
Gain Access
Remedy:
Apply the appropriate patch for your system, as listed in Veritas Document ID: 271040. See References.
References:
- Veritas Document ID: 271040: A security flaw which allows for potential unauthorized root access in VERITAS Cluster Server (tm) for all UNIX platforms has been discovered.
- BID-11421: Veritas Cluster Server Superuser Compromise Vulnerability
- CVE-2004-2205: Unknown vulnerability in Veritas Cluster Server 1.0.1 through 4.0 allows local users to gain root access via unspecified vectors.
- OSVDB ID: 10757: VERITAS Cluster Unspecified Remote Privilege Escalation
- SA12833: VERITAS Cluster Server Unspecified System Compromise Vulnerability
- SECTRACK ID: 1011693: VERITAS Cluster Server Unspecified Flaw Grants Root Access to Remote Users
Platforms Affected:
- Symantec VERITAS Cluster Server 1.0.1 Solaris
- Symantec VERITAS Cluster Server 1.0.2 Solaris
- Symantec VERITAS Cluster Server 1.1 Solaris
- Symantec VERITAS Cluster Server 1.1.1 Solaris
- Symantec VERITAS Cluster Server 1.1.2 Solaris
- Symantec VERITAS Cluster Server 1.2
- Symantec VERITAS Cluster Server 1.3 Solaris
- Symantec VERITAS Cluster Server 1.3 P4
- Symantec VERITAS Cluster Server 1.3 P3
- Symantec VERITAS Cluster Server 1.3 P2
- Symantec VERITAS Cluster Server 1.3 P1
- Symantec VERITAS Cluster Server 1.3 HP-UX
- Symantec VERITAS Cluster Server 1.3
- Symantec VERITAS Cluster Server 1.3 Pre-GA Solaris
- Symantec VERITAS Cluster Server 1.3.1 P3
- Symantec VERITAS Cluster Server 1.3.1 HP-UX
- Symantec VERITAS Cluster Server 2.0 Linux
- Symantec VERITAS Cluster Server 2.0 P1
- Symantec VERITAS Cluster Server 2.0 P3
- Symantec VERITAS Cluster Server 2.0 P4
- Symantec VERITAS Cluster Server 2.0 Solaris
- Symantec VERITAS Cluster Server 2.0 Beta Solaris
- Symantec VERITAS Cluster Server 2.0 GA Solaris
- Symantec VERITAS Cluster Server 2.0 AIX
- Symantec VERITAS Cluster Server 2.0
- Symantec VERITAS Cluster Server 2.0 P2
- Symantec VERITAS Cluster Server 2.1 P1 Linux
- Symantec VERITAS Cluster Server 2.1 Linux
- Symantec VERITAS Cluster Server 2.1
- Symantec VERITAS Cluster Server 2.2 Linux
- Symantec VERITAS Cluster Server 2.2
- Symantec VERITAS Cluster Server 2.2 MP2
- Symantec VERITAS Cluster Server 2.2 MP1
- Symantec VERITAS Cluster Server 2.2 MP1P1 Linux
- Symantec VERITAS Cluster Server 3.5 MP1
- Symantec VERITAS Cluster Server 3.5 MP1J
- Symantec VERITAS Cluster Server 3.5 Update2 HP-UX
- Symantec VERITAS Cluster Server 3.5 Update1 HP-UX
- Symantec VERITAS Cluster Server 3.5 HP-UX
- Symantec VERITAS Cluster Server 3.5 AIX
- Symantec VERITAS Cluster Server 3.5
- Symantec VERITAS Cluster Server 3.5 MP2
- Symantec VERITAS Cluster Server 3.5 MP3 Solaris
- Symantec VERITAS Cluster Server 3.5 MP2 Solaris
- Symantec VERITAS Cluster Server 3.5 MP1 Solaris
- Symantec VERITAS Cluster Server 3.5 Beta Solaris
- Symantec VERITAS Cluster Server 3.5 Solaris
- Symantec VERITAS Cluster Server 3.5 P1
- Symantec VERITAS Cluster Server 3.5.1 AIX
- Symantec VERITAS Cluster Server 4.0 Beta Solaris
- Symantec VERITAS Cluster Server 4.0 Solaris
- Symantec VERITAS Cluster Server 4.0 Beta Linux
- Symantec VERITAS Cluster Server 4.0 Linux
- Symantec VERITAS Cluster Server 4.0 Beta AIX
- Symantec VERITAS Cluster Server 4.0 AIX
Reported:
Oct 15, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
