Symantec VERITAS Backup Exec for Windows Server RPC interface buffer overflow
| backupexec-rpc-interface-bo (28336) |
Description:
Symantec Backup Exec for Windows Server and Remote Agents are vulnerable to a heap-based buffer overflow in the RPC interface. A remote attacker with valid authentication credentials could exploit this vulnerability to overflow a buffer and execute arbitrary code on the system or cause the application to crash.
*CVSS:
| Base Score: | 6 |
| Access Vector: | Remote |
| Access Complexity: | Low |
| Authentication: | Required |
| Confidentiality Impact: | Complete |
| Integrity Impact: | Complete |
| Availability Impact: | Complete |
| Temporal Score: | 4.4 |
| Exploitability: | Unproven |
| Remediation Level: | Official-Fix |
| Report Confidence: | Confirmed |
Consequences:
Gain Access
Remedy:
Refer to Symantec Security Advisory SYM06-014 for upgrade information. See References.
References:
- SYM06-014 : Symantec Backup Exec for Windows Server: RPC Interface Heap Overflow, Authorized User Potential Elevation of Privilege .
- Symantec Web site: Symantec Corp..
- BID-19479: Symantec Backup Exec Multiple Heap Overflow Vulnerabilities
- CVE-2006-4128: Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Backup Exec Continuous Protection Server Remote Agent for Windows Server 10.1 (builds 10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, and 10.1.327.401), and Backup Exec for Windows Server and Remote Agent 9.1 (build 9.1.4691), 10.0 (builds 10.0.5484 and 10.0.5520), and 10.1 (build 10.1.5629) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RPC message.
- SA21472: Backup Exec Remote Agent RPC Interface Buffer Overflows
- SECTRACK ID: 1016683: Symantec Backup Exec RPC Buffer Overflow Lets Remote Authenticated Users Execute Arbitrary Code
- US-CERT VU#647796: Symantec Veritas Backup Exec for Windows Server vulnerable to heap-based buffer overflow
- VUPEN/ADV-2006-3266: Symantec VERITAS Backup Exec Remote Agent RPC Buffer Overflow Vulnerability
Platforms Affected:
- Symantec VERITAS Backup Exec 10.0 Windows
- Symantec VERITAS Backup Exec 10.0.5484 Windows
- Symantec VERITAS Backup Exec 10.0.5520 Windows
- Symantec VERITAS Backup Exec 10.1 Windows
- Symantec VERITAS Backup Exec 10.1.325.6301
- Symantec VERITAS Backup Exec 10.1.326.1401
- Symantec VERITAS Backup Exec 10.1.326.2501
- Symantec VERITAS Backup Exec 10.1.326.3301
- Symantec VERITAS Backup Exec 10.1.327.401
- Symantec VERITAS Backup Exec 10.1.5629 Windows
- Symantec VERITAS Backup Exec 9.1 Windows
- Symantec VERITAS Backup Exec 9.1.4691 Windows
- Symantec VERITAS Backup Exec 9.2 Windows
Reported:
Aug 11, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
