Korean
<< Back
VID 28108
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The Veritas Backup Exec, according to its version number, has a remote buffer overflow vulnerability. Veritas Backup Exec is a backup and recovery software solution for Microsoft Windows and Unix-based operating systems. Veritas Backup Exec versions 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40 are vulnerable to a stack-based buffer overflow. This vulnerability exists because the application fails to carry out proper boundary checks by the Agent Browser service when processing received registration requests with a long hostname. A remote attacker could exploit this vulnerability to execute arbitrary code on the vulnerable host with the privileges of a local administrator or to disable the vulnerable service remotely.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://www.kb.cert.org/vuls/id/907729
http://www.ciac.org/ciac/bulletins/p-066.shtml
http://www.idefense.com/application/poi/display?id=169&type=vulnerabilities
http://secunia.com/advisories/13495/
http://metasploit.com/projects/Framework/exploits.html

* Platforms Affected:
Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68
Veritas Backup Exec 9.x before 9.1.4691 Hotfix 40
Microsoft Windows Any version
Recommendation Upgrade to the latest version of Veritas NetBackup (8.6 Build 3878 or 9.1 Build 4691 SP1 or later), as listed in Veritas Software Support Document ID: 273419 at http://seer.support.veritas.com/docs/273419.htm
Related URL CVE-2004-1172 (CVE)
Related URL 11974 (SecurityFocus)
Related URL 18506 (ISS)