PT-2005-4415 · Sun+1 · Storedge Enterprise Backup+2
Published
2005-12-31
·
Updated
2017-07-11
·
CVE-2005-3658
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMC Legato NetWorker versions 7.1.x through 7.1.3 and versions 7.2.x through 7.2.1.Build.313
Sun Solstice Backup (SBU) versions 6.0 through 6.1
StorEdge Enterprise Backup Software (EBS) versions 7.1 through 7.2L
Description
The issue allows remote attackers to execute arbitrary code or cause a denial of service via malformed RPC packets to specific RPC program numbers, including
390109 (nsrd.exe) and 390113 (nsrexecd.exe).Recommendations
For EMC Legato NetWorker versions 7.1.x through 7.1.3, update to version 7.1.4 or later.
For EMC Legato NetWorker versions 7.2.x through 7.2.1.Build.313, update to version 7.2.1.Build.314 or later.
For Sun Solstice Backup (SBU) versions 6.0 through 6.1, consider disabling the RPC programs
390109 (nsrd.exe) and 390113 (nsrexecd.exe) until a patch is available.
For StorEdge Enterprise Backup Software (EBS) versions 7.1 through 7.2L, restrict access to the RPC programs 390109 (nsrd.exe) and 390113 (nsrexecd.exe) to minimize the risk of exploitation.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emc Legato Networker
Storedge Enterprise Backup
Sun Solstice Backup