cancel
Showing results for 
Search instead for 
Did you mean: 

Backup Exec 12.5 Vulnerable to ShellShock?

Helpmeplease123
Level 1

We are running Backup Exec 12.5, is it at all Vulnerable to ShellShock?

1 ACCEPTED SOLUTION

Accepted Solutions

Sush---
Level 6
Employee Accredited Certified

Hello there,

   Though BE is not installed on Unix as Media server we do have our RALUS agent installed on supported Linux and Unix servers. ShellShock vulnerability is on bash itself. Backup Exec does not distribute linux or bash in its product (any version of BE). So Backup exec is not affected by ShellShock.

   All Linux vendors have issued security advisories for the newly discovered vulnerability including patching information to prevent an attack. So the best way to keep away from ShellShock is apply the patches released by Linux vendors.

Also for more information, other Symantec software (Symantec system Recovery) is not affected too.

Refer: http://www.symantec.com/docs/TECH225068 

 

Regards,

-Sush...

View solution in original post

4 REPLIES 4

CraigV
Moderator
Moderator
Partner    VIP    Accredited

Hi,

 

Doubt it...it appears to be vulnerability in Unix, and BE doesn't install on Unix as a media server at all.

http://www.slate.com/articles/technology/technology/2014/09/shellshock_what_you_need_to_know_about_t...

Thanks!

Sush---
Level 6
Employee Accredited Certified

Hello there,

   Though BE is not installed on Unix as Media server we do have our RALUS agent installed on supported Linux and Unix servers. ShellShock vulnerability is on bash itself. Backup Exec does not distribute linux or bash in its product (any version of BE). So Backup exec is not affected by ShellShock.

   All Linux vendors have issued security advisories for the newly discovered vulnerability including patching information to prevent an attack. So the best way to keep away from ShellShock is apply the patches released by Linux vendors.

Also for more information, other Symantec software (Symantec system Recovery) is not affected too.

Refer: http://www.symantec.com/docs/TECH225068 

 

Regards,

-Sush...

maurijo
Level 6
Partner Accredited

Backup exec server is not vulnerable since you can not intall it on unix or linux server. Only the agent (RALUS) can be installed on linux but then still this is a bash bug and bash is part of the operating system. You should install the security updates released by your os vendor to fix the shellshock vulnerability.

CraigV
Moderator
Moderator
Partner    VIP    Accredited

...not sure why you are simply repeating the same information contained in the 2 posts above?

Thanks!