| VID |
28108 |
| Severity |
40 |
| Port |
139,445 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
The Veritas Backup Exec, according to its version number, has a remote buffer overflow vulnerability. Veritas Backup Exec is a backup and recovery software solution for Microsoft Windows and Unix-based operating systems. Veritas Backup Exec versions 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40 are vulnerable to a stack-based buffer overflow. This vulnerability exists because the application fails to carry out proper boundary checks by the Agent Browser service when processing received registration requests with a long hostname. A remote attacker could exploit this vulnerability to execute arbitrary code on the vulnerable host with the privileges of a local administrator or to disable the vulnerable service remotely.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.kb.cert.org/vuls/id/907729 http://www.ciac.org/ciac/bulletins/p-066.shtml http://www.idefense.com/application/poi/display?id=169&type=vulnerabilities http://secunia.com/advisories/13495/ http://metasploit.com/projects/Framework/exploits.html
* Platforms Affected: Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68 Veritas Backup Exec 9.x before 9.1.4691 Hotfix 40 Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of Veritas NetBackup (8.6 Build 3878 or 9.1 Build 4691 SP1 or later), as listed in Veritas Software Support Document ID: 273419 at http://seer.support.veritas.com/docs/273419.htm |
| Related URL |
CVE-2004-1172 (CVE) |
| Related URL |
11974 (SecurityFocus) |
| Related URL |
18506 (ISS) |
|