PT-2006-2029 · Veritas · Netbackup
Published
2006-03-28
·
Updated
2018-10-18
·
CVE-2006-0991
CVSS v2.0
7.1
High
| Vector | AV:N/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetBackup version 6.0 for Windows
Description
The issue is related to a buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) that allows remote attackers to execute arbitrary code. This is achieved by sending crafted "Request Service" packets to the vnetd service, which listens on TCP port 13724.
Recommendations
For NetBackup version 6.0 for Windows, consider restricting access to the vnetd service on TCP port 13724 until a patch is available. As a temporary workaround, disabling the bpspsserver daemon may help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbackup