SID 12904

References

Bugtraq

CVE

Msg

"EXPLOIT Veritas NetBackup vmd shared library buffer overflow attempt"

Summary

This event is generated when an attempt is made to exploit a known vulnerability in Netbackup.

Classtype

attempted-admin

Impact

Denial of Service. Information disclosure. Loss of integrity. Complete admin access.

Detailed Information

Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute arbitrary code via a crafted packet.

Affected Systems

  • Symantec Veritas Netbackup 9

Ease Of Attack

Simple.

False Positives

None known.

False Negatives

None known.

Corrective Action

Upgrade to the latest non-affected version of the software.

Apply the appropriate vendor supplied patches.

Contributors

  • Sourcefire Vulnerability Research Team
  • This document was generated from data supplied by the National Vulnerability Database. A product of the National Institute of Standards and Technology.
  • For more information see http://nvd.nist.gov/