| VID |
12073 |
| Severity |
40 |
| Port |
10000 |
| Protocol |
TCP |
| Class |
Daemon |
| Detailed Description |
The Backup Exec Remote Agent is vulnerable to a buffer overflow vulnerability in authentication request. VERITAS Backup Exec is a data backup and recovery solution with support for over the network backup. The VERITAS Backup Exec Agent runs on systems to be backed up listening on TCP port 10000 and is responsible for accepting connections from the backup server when a backup is to occur. The Backup Exec Remote Agent for Microsoft Windows Servers is vulnerable to a buffer overflow vulnerability due to incorrect validation on authentication requests. A remote attacker could exploit this vulnerability to execute arbitrary code on computers where the Remote Agent is installed and to gain administrative control.
* References: http://seer.support.veritas.com/docs/276604.htm http://xforce.iss.net/xforce/alerts/id/197 http://www.kb.cert.org/vuls/id/492105 http://www.idefense.com/application/poi/display?id=272&type=vulnerabilities
* Platforms Affected: VERITAS Backup Exec 10.0 Win rev.5484 VERITAS Backup Exec 9.0 Win rev 4367 VERITAS Backup Exec 9.0 Win rev4454 VERITAS Backup Exec 9.0.4019 VERITAS Backup Exec 9.0.4170 VERITAS Backup Exec 9.0.4172 VERITAS Backup Exec 9.0.4174 VERITAS Backup Exec 9.0.4202 VERITAS Backup Exec 9.1 Win rv4691 VERITAS Backup Exec 9.1.1067.2 VERITAS Backup Exec 9.1.1067.3 VERITAS Backup Exec 9.1.1127.1 VERITAS Backup Exec 9.1.1151.1 VERITAS Backup Exec 9.1.1152 VERITAS Backup Exec 9.1.1152.4 VERITAS Backup Exec 9.1.1154 VERITAS Backup Exec 9.1.306 VERITAS Backup Exec 9.1.307 Microsoft Windows Any version Novell NetWare Any version |
| Recommendation |
Apply the appropriate hotfix for your system, as listed in the Veritas Document ID: 276604 at http://seer.support.veritas.com/docs/276604.htm |
| Related URL |
CVE-2005-0773 (CVE) |
| Related URL |
14019,14021,14022 (SecurityFocus) |
| Related URL |
21113 (ISS) |
|