Vulnerability Note VU#907729
Veritas Backup Exec registration request buffer overflow
OverviewCertain versions of Veritas Backup Exec 8.x and 9.x can be remotely exploited to allow execution of arbitrary code on affected servers.
I. DescriptionA buffer overflow exists in Veritas Backup Exec 8.x (prior to 8.60.3878 Hotfix 68), and 9.x (pritor to 9.1.4691 Hotfix 40). A stack-based buffer can be overwritten when certain registration requests containing overly long hostnames are sent to vulnerable servers.
Exploits for this vulnerability have been made available via public web sites. Active exploitation of this vulnerability has been reported.
II. ImpactA remote intruder may be able to crash affected systems or execute arbitrary code with the privileges of the running service which may include domain-wide administrative rights.
III. SolutionPlease see the vendor documents with patch information to resolve this issue:
http://seer.support.veritas.com/docs/273419.htm
http://seer.support.veritas.com/docs/273420.htm
http://seer.support.veritas.com/docs/273422.htm
http://seer.support.veritas.com/docs/273850.htm
IV. Workarounds
Restrict network access to 6101/tcp on affected servers
Systems Affected
References
http://seer.support.veritas.com/docs/273419.htm
http://seer.support.veritas.com/docs/273420.htm
http://seer.support.veritas.com/docs/273422.htm
http://seer.support.veritas.com/docs/273850.htm
http://seer.support.veritas.com/docs/240870.htm
http://veritas.com/Products/www?c=product&refId=57
http://secunia.com/advisories/13495/
http://www.idefense.com/application/poi/display?id=169&type=vulnerabilities&flashstatus=false
http://securitytracker.com/alerts/2004/Dec/1012597.html
http://www.securityfocus.com/bid/11974
http://xforce.iss.net/xforce/xfdb/18506
http://jvn.jp/cert/JVNVU%23907729/index.html
Credit
iDefense has credited an anonymous contributor and Patrik Karlsson for discovering this vulnerability.
This document was written by Jeffrey S. Havrilla.
Other Information
| Date Public: | 2004-12-15 |
| Date First Published: | 2005-01-14 |
| Date Last Updated: | 2006-05-01 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2004-1172 |
| NVD-ID(s): | CVE-2004-1172 |
| US-CERT Technical Alerts: | |
| Metric: | 17.82 |
| Document Revision: | 16 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|