=====================================================================
                                      CERT-Renater

                           Note d'Information No. 2006/VULN041
_____________________________________________________________________

DATE                      : 27/01/2006

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running Sun StorEdge Enterprise Backup
                                 Software, Solstice Backup.

======================================================================

Sun(sm) Alert Notification
       * Sun Alert ID: 102148
       * Synopsis: Security Vulnerabilities in Sun StorEdge Enterprise
         Backup Software (EBS)
       * Category: Security
       * Product: Sun StorEdge Enterprise Backup Software 7.2, Sun StorEdge
         Enterprise Backup Software 7.0, Solstice Backup 6.0, Solstice
         Backup 6.1, Sun StorEdge Enterprise Backup Software 7.1
       * BugIDs: 6371520
       * Avoidance: Patch
       * State: Workaround
       * Date Released: 25-Jan-2006
       * Date Closed:
       * Date Modified:

1. Impact

     There are three vulnerabilities in Sun StorEdge Enterprise Backup
     Software (EBS), which affect both the client and server applications.
     Two of the vulnerabilities could permit a local or remote unauthorized
     user to gain access to a host system and execute arbitrary code. One
     may allow a local or remote unauthenticated user to cause a system
     crash on the server, which would lead to a Denial of Service (DoS)
     condition.

     Note: To date there are no reported incidences of this issue having
     occurred in a "live" (public) environment.

     These issues are referenced in the following iDEFENSE
     (http://www.idefense.com) documents:

     IDEF1237 "...Networker nsrd.exe DoS Vulnerability" at
     http://www.idefense.com/intelligence/vulnerabilities/display.php?id=375

     IDEF1238 "...Networker nsrexecd.exe Heap Overflow Vulnerability" at
     http://www.idefense.com/intelligence/vulnerabilities/display.php?id=374

     IDEF1239 "...Networker nsrd.exe Heap Overflow Vulnerability" at
     http://www.idefense.com/intelligence/vulnerabilities/display.php?id=373

     and also

     CAN-2005-3658 at
     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3658

     CAN-2005-3659 at
     http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3659

2. Contributing Factors

     These issues can occur in the following releases:

     SPARC Platform
       * Solstice Backup (SBU) 6.0
       * Solstice Backup (SBU) 6.1
       * Sun StorEdge Enterprise Backup Software (EBS) 7.1 without
         patch 116826-06
       * Sun StorEdge Enterprise Backup Software (EBS) 7.1L without
         patch 116828-04
       * Sun StorEdge Enterprise Backup Software (EBS) 7.2 (32 bit)
       * Sun StorEdge Enterprise Backup Software (EBS) 7.2 (64 bit)
       * Sun StorEdge Enterprise Backup Software (EBS) 7.2L

     x86 Platform
       * Solstice Backup (SBU) 6.0
       * Solstice Backup (SBU) 6.1
       * Sun StorEdge Enterprise Backup Software (EBS) 7.1 without
         patch 116827-07
       * Sun StorEdge Enterprise Backup Software (EBS) 7.2

     Note: These issues are known to affect all Sun StorEdge Enterprise
     Backup Software (EBS) versions prior to 7.3 release.

     To determine if Solstice Backup (SBU) is installed on a system, the
     following command can be run:
      $ pkginfo | grep SUNWsbu

     To determine the version of Solstice Backup (SBU) on a system, the
     following command can be run:
      $ pkginfo -l SUNWsbuX

     (where 'X' is one of the last characters of the EBS package names
     found from the above pkginfo(1) command).

     To determine if Sun StorEdge EBS is installed on a system, the
     following command can be run:
      $ pkginfo | grep SUNWebs

     To determine the version of Sun StorEdge EBS on a system, the
     following command can be run:
      $ pkginfo -l SUNWebsX

     (where 'X' is one of the last characters of the EBS package names
     found from the above pkginfo(1) command).

3. Symptoms

     There are no reliable symptoms that would indicate the described
     issues have been exploited.

4. Relief/Workaround

     There is no workaround to these issues. Please see the Resolution
     section below.

5. Resolution

     These issues are addressed in the following releases:

     SPARC Platform
       * Sun StorEdge Enterprise Backup Software (EBS) 7.1 with
         patch 116826-06 or later
       * Sun StorEdge Enterprise Backup Software (EBS) 7.1L with
         patch 116828-04 or later
       * Sun StorEdge Enterprise Backup Software (EBS) 7.3

     x86 Platform
       * Sun StorEdge Enterprise Backup Software (EBS) 7.1 with
         patch 116827-07 or later
       * Sun StorEdge Enterprise Backup Software (EBS) 7.3

     Notes:
      1. Sun StorEdge Enterprise Backup Software (EBS) 7.0 and earlier will
         require an upgrade to a later release with the associated patches
         installed to address these issues.
      2. The patches mentioned in this Sun Alert are for Solaris SPARC and
         Solaris x86/x64 platform support only. Non-Solaris UNIX platforms
         and other Sun StorEdge Enterprise Backup Software (EBS) supported
         platforms can go to the following location for the resolution to
         this issue:

     http://www.legato.com/support/websupport/patches_updates/networker.htm

     A final resolution is pending completion for EBS 7.2

     This Sun Alert notification is being provided to you on an "AS IS"
     basis. This Sun Alert notification may contain information provided by
     third parties. The issues described in this Sun Alert notification may
     or may not impact your system(s). Sun makes no representations,
     warranties, or guarantees as to the information contained herein. ANY
     AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION
     WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR
     NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT
     YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT,
     INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE
     OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN.
     This Sun Alert notification contains Sun proprietary and confidential
     information. It is being provided to you pursuant to the provisions of
     your agreement to purchase services from Sun, or, if you do not have
     such an agreement, the Sun.com Terms of Use. This Sun Alert
     notification may only be used for the purposes contemplated by these
     agreements.

     Copyright 2000-2005 Sun Microsystems, Inc., 4150 Network Circle, Santa
     Clara, CA 95054 U.S.A. All rights reserved

======================================================================

             =========================================================
             Les serveurs de référence du CERT-Renater
             http://www.urec.fr/securite
             http://www.cru.fr/securite
             http://www.renater.fr
             =========================================================
             + CERT-RENATER          | tel : 01-53-94-20-44          +
             + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
             + 75013 Paris           | email: certsvp@renater.fr     +
             =========================================================


