===================================================================== CERT-Renater Note d'Information No. 2008/VULN426 _____________________________________________________________________ DATE : 14/10/2008 HARDWARE PLATFORM(S) : / OPERATING SYSTEM(S) : Windows running Lenovo Rescue and Recovery version 4.20. ====================================================================== http://www-307.ibm.com/pc/support/site.wss/MIGR-70699.html ______________________________________________________________________ Update available for vulnerability in version 4.20 of Lenovo Rescue and Recovery Summary This Security Bulletin addresses a vulnerability in Rescue and Recovery version 4.20. This vulnerability could allow an attacker to run code with elevated privileges on the affected system. This vulnerability has been assigned a serious severity rating. It is recommended that users update to the most current version of Lenovo Rescue and Recovery available. Affected configurations Systems with the following versions of Rescue and Recovery installed: * Lenovo Rescue and Recovery 4.20.0512 Vista * Lenovo Rescue and Recovery 4.20.0511 XP and 2000 Solution Lenovo Rescue and Recovery on Windows Lenovo strongly recommends upgrading to Lenovo Rescue and Recovery 4.21, available from the following site: http://www.lenovo.com/support/site.wss/MIGR-4Q2QAK.html Additional information Acknowledgment Lenovo would like to thank ISec Partners for reporting the vulnerability described in CVE-2006-5857 and for working with us to help protect our customers' security. Copyright © 2008 Lenovo. All rights reserved. Applicable countries and regions Worldwide Document id: MIGR-70699 Last modified: 2008-10-09 Copyright © 2008 IBM Corporation Copyright © Lenovo 2008, all rights reserved ====================================================================== ========================================================= Les serveurs de référence du CERT-Renater http://www.urec.fr/securite http://www.cru.fr/securite http://www.renater.fr ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 151 bd de l'Hopital | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================