Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

675

November 3rd, 2008 06:00

emc198683, ESA-08-013

I'm confused about this announcement:

ESA-08-013: NetWorker nsrexecd.exe Resource Exhaustion issue."
emc198683

The article says that Exchange module 5.1 and prior are affected. It also says that the package that contains the fix can be downloaded from the section "NetWorker Module for Exchange 5.1 SP1. This includes Security Vulnerability LGTsc19158 fix." However, that section does not exist. Also, the packages listed for Exchange were posted on 9/15/08, well before this announcement. And, the Exchange package does not seem to contain a nsrexecd.exe which is the process identified as having the vulnerability.

The Networker package is fairly clear, Client 7.3 SP4 build 565 takes care of it. The Exchange module is not so clear.

Is there an Exchange module that I am missing? Is the Exchange module affected somewhere other than nsrexecd? Does the 9/15/08 release contain the fix?

Thanks,

PTD

14.3K Posts

November 3rd, 2008 12:00

As for Exchange module, build 299 takes care of it. Exchange release note should contain that information.

724 Posts

November 3rd, 2008 10:00

Well, if it says that 5.1 SP1 fixes it, just download this version (it's the version available in the download page).

The nsrexecd.exe is installed with the Client software, but it's used for communication with the server, even by the module's commands, so I believe that you have to fix both side (client and module) to avoid the problem.

40 Posts

November 3rd, 2008 12:00

I guess my confusion comes from the fact that every other package on the download site that is identified as vulnerable actually has a download section that contains the words "This includes Security Vulnerability LGTsc19158 fix". The Exchange section does not.

However, it is in the release notes as you said.

Thanks for the help!

40 Posts

November 8th, 2008 13:00

Follow-up,

Although the release notes do say that the problem has been fixed in SP1, the release on the downloads is build 294, not 299. I installed 294 and hopefully that addresses the 198683 issue.

Are you sure it should be 299?

Thanks,

14.3K Posts

November 9th, 2008 12:00

Yes.

40 Posts

November 9th, 2008 15:00

If 294 is the only package listed on the downloads, how would I get 299?

14.3K Posts

November 9th, 2008 15:00

You will need to ask your support to provide it to you (or EMC if you have direct support).
No Events found!

Top