PT-2005-3945 · Veritas · Veritas Netbackup Enterprise Server
Published
2005-11-18
·
Updated
2017-07-11
·
CVE-2005-3116
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VERITAS NetBackup Enterprise Server versions 5.0 MP1 through 5.0 MP5
VERITAS NetBackup Enterprise Server versions 5.1 up to 5.1 MP3A
Description
The issue is related to a stack-based buffer overflow in a shared library used by the Volume Manager daemon. This allows remote attackers to execute arbitrary code via a crafted packet.
Recommendations
For VERITAS NetBackup Enterprise Server versions 5.0 MP1 through 5.0 MP5, update to a version outside of this range to mitigate the risk.
For VERITAS NetBackup Enterprise Server versions 5.1 up to 5.1 MP3A, update to a version later than 5.1 MP3A to resolve the issue.
As a temporary workaround, consider restricting access to the Volume Manager daemon to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veritas Netbackup Enterprise Server