googlebot1

updated

10 years ago

G

googlebot1

1 Rookie

2 Posts

0

1118

December 7th, 2016 09:00

ESA-2016-111: Privilege Escalation Vulnerability

Hello,

Was the privilege escalation vulnerability mentioned in ESA-2016-111 (CVE-2016-0909) fixed in 7.3.1?

The advisory states:

"The following EMC Avamar release contains a resolution to this vulnerability: Avamar Server 7.3.0-233 with hotfix 263301"

The announcement on seclists seems to imply that 7.3.1 is not affected by this vulnerability:

"Affected products: 

• EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3.0 and older"

http://seclists.org/bugtraq/2016/Oct/att-45/ESA-2016-111.txt

However, I can't find anything specifically stating that the vulnerability was fixed in the release notes except maybe "Secure session tickets" or "Postgres updated to the latest version".

Thanks for your assistance.