PT-2005-3833 · Veritas+1 · Veritas Storagecentral+3
Mark Litchfield
·
Published
2005-09-20
·
Updated
2008-09-05
·
CVE-2005-2996
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VERITAS Storage Exec versions prior to 5.3 Hotfix 9
VERITAS StorageCentral versions prior to 5.2 Hot Fix 2
Description
The issue is related to multiple heap-based and stack-based buffer overflows in certain DCOM server components. This allows remote attackers to execute arbitrary code via certain ActiveX controls.
Recommendations
For VERITAS Storage Exec versions prior to 5.3 Hotfix 9, apply Hotfix 9 to resolve the issue.
For VERITAS StorageCentral versions prior to 5.2 Hot Fix 2, apply Hot Fix 2 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Activex
Dcom
Veritas Storage Exec
Veritas Storagecentral