PT-2005-4415 · Sun+1 · Storedge Enterprise Backup+2

Published

2005-12-31

·

Updated

2017-07-11

·

CVE-2005-3658

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions EMC Legato NetWorker versions 7.1.x through 7.1.3 and versions 7.2.x through 7.2.1.Build.313 Sun Solstice Backup (SBU) versions 6.0 through 6.1 StorEdge Enterprise Backup Software (EBS) versions 7.1 through 7.2L
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service via malformed RPC packets to specific RPC program numbers, including 390109 (nsrd.exe) and 390113 (nsrexecd.exe).
Recommendations For EMC Legato NetWorker versions 7.1.x through 7.1.3, update to version 7.1.4 or later. For EMC Legato NetWorker versions 7.2.x through 7.2.1.Build.313, update to version 7.2.1.Build.314 or later. For Sun Solstice Backup (SBU) versions 6.0 through 6.1, consider disabling the RPC programs 390109 (nsrd.exe) and 390113 (nsrexecd.exe) until a patch is available. For StorEdge Enterprise Backup Software (EBS) versions 7.1 through 7.2L, restrict access to the RPC programs 390109 (nsrd.exe) and 390113 (nsrexecd.exe) to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-3658

Affected Products

Emc Legato Networker
Storedge Enterprise Backup
Sun Solstice Backup