PT-2006-4969 · Symantec+1 · Symantec Veritas Backup Exec+3

Nicolas Pouvesle

·

Publicado

2006-08-14

·

Atualizado

2018-10-17

·

CVE-2006-4128

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server versions 9.1 through 9.2 Symantec Backup Exec Continuous Protection Server Remote Agent for Windows Server version 10.1 Symantec Backup Exec for Windows Server and Remote Agent versions 9.1 through 10.1
Description The issue is related to multiple heap-based buffer overflows that can be triggered by remote attackers sending a crafted RPC message. This can cause a denial of service, resulting in an application crash, and potentially allow the execution of arbitrary code.
Recommendations For Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server versions 9.1 through 9.2, update to a version that is not affected by this issue. For Symantec Backup Exec Continuous Protection Server Remote Agent for Windows Server version 10.1, update to a version that is not affected by this issue. For Symantec Backup Exec for Windows Server and Remote Agent versions 9.1 through 10.1, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the RPC service to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4128

Produtos afetados

Backup Exec
Symantec Backup Exec Continuous Protection Server
Symantec Veritas Backup Exec
Windows Server