Korean
<< Back
VID 12073
Severity 40
Port 10000
Protocol TCP
Class Daemon
Detailed Description The Backup Exec Remote Agent is vulnerable to a buffer overflow vulnerability in authentication request. VERITAS Backup Exec is a data backup and recovery solution with support for over the network backup. The VERITAS Backup Exec Agent runs on systems to be backed up listening on TCP port 10000 and is responsible for accepting connections from the backup server when a backup is to occur. The Backup Exec Remote Agent for Microsoft Windows Servers is vulnerable to a buffer overflow vulnerability due to incorrect validation on authentication requests. A remote attacker could exploit this vulnerability to execute arbitrary code on computers where the Remote Agent is installed and to gain administrative control.

* References:
http://seer.support.veritas.com/docs/276604.htm
http://xforce.iss.net/xforce/alerts/id/197
http://www.kb.cert.org/vuls/id/492105
http://www.idefense.com/application/poi/display?id=272&type=vulnerabilities

* Platforms Affected:
VERITAS Backup Exec 10.0 Win rev.5484
VERITAS Backup Exec 9.0 Win rev 4367
VERITAS Backup Exec 9.0 Win rev4454
VERITAS Backup Exec 9.0.4019
VERITAS Backup Exec 9.0.4170
VERITAS Backup Exec 9.0.4172
VERITAS Backup Exec 9.0.4174
VERITAS Backup Exec 9.0.4202
VERITAS Backup Exec 9.1 Win rv4691
VERITAS Backup Exec 9.1.1067.2
VERITAS Backup Exec 9.1.1067.3
VERITAS Backup Exec 9.1.1127.1
VERITAS Backup Exec 9.1.1151.1
VERITAS Backup Exec 9.1.1152
VERITAS Backup Exec 9.1.1152.4
VERITAS Backup Exec 9.1.1154
VERITAS Backup Exec 9.1.306
VERITAS Backup Exec 9.1.307
Microsoft Windows Any version
Novell NetWare Any version
Recommendation Apply the appropriate hotfix for your system, as listed in the Veritas Document ID: 276604 at http://seer.support.veritas.com/docs/276604.htm
Related URL CVE-2005-0773 (CVE)
Related URL 14019,14021,14022 (SecurityFocus)
Related URL 21113 (ISS)