CVE-2006-4128
Summary
| CVE | CVE-2006-4128 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-14 23:04:00 UTC |
| Updated | 2018-10-17 21:33:00 UTC |
| Description | Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Backup Exec Continuous Protection Server Remote Agent for Windows Server 10.1 (builds 10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, and 10.1.327.401), and Backup Exec for Windows Server and Remote Agent 9.1 (build 9.1.4691), 10.0 (builds 10.0.5484 and 10.0.5520), and 10.1 (build 10.1.5629) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RPC message. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec Veritas | Backup Exec | 10.0 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.0_build10.0.5484 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.0_build10.0.5520 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.1 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.1.325.6301 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.326.1401 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.326.2501 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.326.3301 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.327.401 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1_build10.1.5629 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 9.1 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 9.1_build9.1.4691 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 9.2 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.0 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.0_build10.0.5484 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.0_build10.0.5520 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.1 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 10.1.325.6301 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.326.1401 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.326.2501 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.326.3301 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1.327.401 | All | All | All |
| Application | Symantec Veritas | Backup Exec | 10.1_build10.1.5629 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 9.1 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 9.1_build9.1.4691 | All | windows_server_remote_agent | All |
| Application | Symantec Veritas | Backup Exec | 9.2 | All | windows_server_remote_agent | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Symantec Backup Exec for Windows Server: RPC Interface Heap Overflow, Authorized User Potential Elevation of Privilege | CONFIRM | securityresponse.symantec.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Symantec Redirect | CONFIRM | seer.entsupport.symantec.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Symantec Backup Exec Multiple Heap Overflow Vulnerabilities | BID | www.securityfocus.com | |
| VU#647796 - Symantec Veritas Backup Exec for Windows Server vulnerable to heap-based buffer overflow | CERT-VN | www.kb.cert.org | US Government Resource |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Secunia - Advisories - Backup Exec Remote Agent RPC Interface Buffer Overflows | SECUNIA | secunia.com | Vendor Advisory |
| SecurityReason - SYM06-014 Symantec Backup Exec Internal RPC Overflow | SREASON | securityreason.com | |
| SecurityTracker.com Archives - Symantec Backup Exec RPC Buffer Overflow Lets Remote Authenticated Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.