SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#907729

Veritas Backup Exec registration request buffer overflow

Overview

Certain versions of Veritas Backup Exec 8.x and 9.x can be remotely exploited to allow execution of arbitrary code on affected servers.

I. Description

A buffer overflow exists in Veritas Backup Exec 8.x (prior to 8.60.3878 Hotfix 68), and 9.x (pritor to 9.1.4691 Hotfix 40). A stack-based buffer can be overwritten when certain registration requests containing overly long hostnames are sent to vulnerable servers.

Exploits for this vulnerability have been made available via public web sites. Active exploitation of this vulnerability has been reported.

II. Impact

A remote intruder may be able to crash affected systems or execute arbitrary code with the privileges of the running service which may include domain-wide administrative rights.

III. Solution

Please see the vendor documents with patch information to resolve this issue:


http://seer.support.veritas.com/docs/273419.htm
http://seer.support.veritas.com/docs/273420.htm
http://seer.support.veritas.com/docs/273422.htm
http://seer.support.veritas.com/docs/273850.htm

IV. Workarounds


Restrict network access to 6101/tcp on affected servers

Systems Affected

VendorStatusDate NotifiedDate Updated
HitachiVulnerable16-Feb-2005
NEC CorporationVulnerable2-Feb-2005
Veritas SOFTWAREVulnerable14-Jan-2005

References


http://seer.support.veritas.com/docs/273419.htm
http://seer.support.veritas.com/docs/273420.htm
http://seer.support.veritas.com/docs/273422.htm
http://seer.support.veritas.com/docs/273850.htm
http://seer.support.veritas.com/docs/240870.htm
http://veritas.com/Products/www?c=product&refId=57
http://secunia.com/advisories/13495/
http://www.idefense.com/application/poi/display?id=169&type=vulnerabilities&flashstatus=false
http://securitytracker.com/alerts/2004/Dec/1012597.html
http://www.securityfocus.com/bid/11974
http://xforce.iss.net/xforce/xfdb/18506
http://jvn.jp/cert/JVNVU%23907729/index.html

Credit

iDefense has credited an anonymous contributor and Patrik Karlsson for discovering this vulnerability.

This document was written by Jeffrey S. Havrilla.

Other Information

Date Public:2004-12-15
Date First Published:2005-01-14
Date Last Updated:2006-05-01
CERT Advisory: 
CVE-ID(s):CVE-2004-1172
NVD-ID(s):CVE-2004-1172
US-CERT Technical Alerts: 
Metric:17.82
Document Revision:16

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader