SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#377441

Symantec VERITAS NetBackup contains a buffer overflow vulnerability in the Sharepoint Services daemon

Overview

The Symantec VERITAS NetBackup Volume Manager daemon contains a buffer overflow vulnerability which may allow a remote, unauthenticated attacker to execute arbitrary code.

I. Description

Symantec VERITAS NetBackup is a client/server based backup software solution. The Sharepoint Services server (bpspsserver) daemon is enabled by default on both servers and clients in the NetBackup 6.0 release for Windows, and is used to support Microsoft SharePoint Servers on a network. A buffer overflow vulnerability exists in this component that could allow a remote attacker to execute code on a vulnerable system.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system.

III. Solution

Install an update

Symantec has provided updates for the vulnerable software in Security Advisory SYM06-006.

Disable or remove service for Microsoft Sharepoint Servers if not required

Symantec has provided several workarounds for this vulnerability in Security Advisory SYM06-006, including disabling or removing the Sharepoint Services server.

Systems Affected

VendorStatusDate NotifiedDate Updated
Symantec, Inc.Vulnerable29-Mar-2006

References


http://www.tippingpoint.com/security/advisories/TSRT-06-01.html
http://secunia.com/advisories/19417/

Credit

Thanks to TippingPoint Security Research for reporting this vulnerability.

This document was written by Chad R Dougherty.

Other Information

Date Public:2006-03-27
Date First Published:2006-03-29
Date Last Updated:2007-01-12
CERT Advisory: 
CVE-ID(s):CVE-2006-0991
NVD-ID(s):CVE-2006-0991
US-CERT Technical Alerts: 
Metric:16.03
Document Revision:5

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader