-
CVE-2017-3169 httpd: mod_ssl NULL pointer dereference
CVE ID CVE-2017-3169 DESCRIPTION A NULL pointer dereference flaw was found in the httpd's mod_ssl module. A remote attacker could use this flaw to cause an httpd child process to crash if another module used by httpd called a certain API function during the processing of an HTTPS request. Unitrends risk assessment: Medium,…
-
CVE-2017-1000366: glibc: manipulate heap/stack via LD_LIBRARY_PATH
CVE ID CVE-2017-1000366 DESCRIPTION glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of…
-
CVE-2016-7406: Format string vulnerability in Dropbear SSH
SUMMARY False positive CVE ID CVE-2016-7406 CVE-2016-7407 CVE-2016-7408 CVE-2016-7409 DESCRIPTION Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument. Unitrends assessment: OS software is Not…
-
CVE-2016-10009 openssh: loading of untrusted PKCS#11 modules in ssh-agent
CVE ID CVE-2016-10009 DESCRIPTION It was found that ssh-agent could load PKCS#11 modules from arbitrary paths. An attacker having control of the forwarded agent-socket on the server, and the ability to write to the filesystem of the client host, could use this flaw to execute arbitrary code with the privileges of the user…
-
How to disable SMB2 enforcement
SUMMARY Disable SMB2-only enforcement to allow Sharepoint backups, Oracle backups or Hyper-V Instant Recovery ISSUE Unitrends provides regular security patches to address vulnerabilities as discussed in Unitrends Response to certain security vulnerabilities (CVEs) - Reference Article. As part of these security patches, the…
-
Release Notes for Recovery Series and Unitrends Backup 10.3.2
DESCRIPTION This document describes enhancements and fixes introduced in the 10.3.2 release. For upgrade instructions and considerations, reference the Upgrade Guide for Recovery Series and Unitrends Backup. Enhancements Unitrends 10.3.2 builds on the success of Unitrends 10.3.1 with the following enhancements:* Appliance…
-
Release Notes for Recovery Series and Unitrends Backup 9.1.1
DESCRIPTION This document describes improvements introduced in the 9.1.1 release for the current user interface. instead. For details on customer-discovered issues that were promptly resolved in this release, see Customer Resolved Defects For Unitrends Backup and Recovery Series 9.1.1. For complete upgrade instructions and…
-
Release notes for Recovery Series and Unitrends Backup Release 10.1.1
DESCRIPTION This document describes new features introduced in the 10.1.1-3 release. For complete upgrade instructions and considerations, see the AHV Protection Guide. Release 10.1.1-3 introduces host-level protection of Acropolis Hypervisor (AHV) virtual machines. With host-level protection, virtual machines are backed…
-
Release Notes for Recovery Series and Unitrends Backup 9.2 - Legacy Interface
DESCRIPTION This document describes new features introduced in the 9.2 release for the legacy user interface. If you are using the current UI, see the Release Notes for Recovery Series and Unitrends Backup 9.2 instead. For details on customer-discovered issues that were promptly resolved in this release, see the Customer…
-
How to identify the version of the installed security patch
SUMMARY Confirm the version of the running security patch RESOLUTION Run the command below to determine the version of the installed security patch. rpm -q unitrends-security Example:[root@UnitrendsSystem ~]# rpm -q unitrends-securityunitrends-security-10.3.3-0.201902011747.CentOS6.x86_64 To see when the last security…