Symantec VERITAS Backup Exec for Windows Server RPC interface buffer overflow

backupexec-rpc-interface-bo (28336) The risk level is classified as HighHigh Risk

Description:

Symantec Backup Exec for Windows Server and Remote Agents are vulnerable to a heap-based buffer overflow in the RPC interface. A remote attacker with valid authentication credentials could exploit this vulnerability to overflow a buffer and execute arbitrary code on the system or cause the application to crash.

Platforms Affected:

  • Symantec, VERITAS Backup Exec 10.0 Windows
  • Symantec, VERITAS Backup Exec 10.0.5484 Windows
  • Symantec, VERITAS Backup Exec 10.0.5520 Windows
  • Symantec, VERITAS Backup Exec 10.1 Windows
  • Symantec, VERITAS Backup Exec 10.1.325.6301
  • Symantec, VERITAS Backup Exec 10.1.326.1401
  • Symantec, VERITAS Backup Exec 10.1.326.2501
  • Symantec, VERITAS Backup Exec 10.1.326.3301
  • Symantec, VERITAS Backup Exec 10.1.327.401
  • Symantec, VERITAS Backup Exec 10.1.5629 Windows
  • Symantec, VERITAS Backup Exec 9.1 Windows
  • Symantec, VERITAS Backup Exec 9.1.4691 Windows
  • Symantec, VERITAS Backup Exec 9.2 Windows

Remedy:

Refer to Symantec Security Advisory SYM06-014 for upgrade information. See References.

Consequences:

Gain Access

References:

  • SYM06-014 , Symantec Backup Exec for Windows Server: RPC Interface Heap Overflow, Authorized User Potential Elevation of Privilege at http://www.symantec.com/avcenter/security/Content/2006.08.11.html.
  • Symantec Web site, Symantec Corp. at http://www.symantec.com/index.htm.
  • BID-19479: Symantec Backup Exec Multiple Heap Overflow Vulnerabilities
  • CVE-2006-4128: Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Backup Exec Continuous Protection Server Remote Agent for Windows Server 10.1 (builds 10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, and 10.1.327.401), and Backup Exec for Windows Server and Remote Agent 9.1 (build 9.1.4691), 10.0 (builds 10.0.5484 and 10.0.5520), and 10.1 (build 10.1.5629) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RPC message.
  • SA21472: Backup Exec Remote Agent RPC Interface Buffer Overflows
  • SECTRACK ID: 1016683: Symantec Backup Exec RPC Buffer Overflow Lets Remote Authenticated Users Execute Arbitrary Code
  • US-CERT VU#647796: Symantec Veritas Backup Exec for Windows Server vulnerable to heap-based buffer overflow
  • VUPEN/ADV-2006-3266: Symantec VERITAS Backup Exec Remote Agent RPC Buffer Overflow Vulnerability

Reported:

Aug 11, 2006

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page