VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vulnerability
BID:11974
Info
VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11974 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1172 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2004 12:00AM |
| Updated: | Nov 01 2007 09:56PM |
| Credit: | This issue is credited to an anonymous researcher and Patrik Karlsson. |
| Vulnerable: |
Veritas Software Backup Exec for Windows Servers 9.1 Veritas Software Backup Exec for Windows Servers 9.0 Veritas Software Backup Exec for Windows Servers 8.6.3878 Veritas Software Backup Exec for Windows Servers 8.6 Veritas Software Backup Exec for Windows Servers 8.5.3572 Veritas Software Backup Exec for Windows Servers 8.5 Veritas Software Backup Exec for Windows Servers 8.0.3315 Veritas Software Backup Exec for Windows Servers 8.0 Veritas Software Backup Exec for Windows Servers 7.3.2575 |
| Not Vulnerable: | |
Discussion
VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vulnerability
Veritas Backup Exec is prone to a remote buffer-overflow vulnerability because the application fails to carry out proper boundary checks before copying user-supplied data into sensitive process buffers. A remote attacker can exploit this issue to execute arbitrary code on a vulnerable computer leading to a complete compromise.
This issue presents itself in an unspecified function that is responsible for handling registration requests. This function is part of the Agent Browser service code.
Veritas Backup Exec is prone to a remote buffer-overflow vulnerability because the application fails to carry out proper boundary checks before copying user-supplied data into sensitive process buffers. A remote attacker can exploit this issue to execute arbitrary code on a vulnerable computer leading to a complete compromise.
This issue presents itself in an unspecified function that is responsible for handling registration requests. This function is part of the Agent Browser service code.
Exploit / POC
VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit has been released as part of the MetaSploit Framework 2.3.
An additional exploit has been released.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit has been released as part of the MetaSploit Framework 2.3.
An additional exploit has been released.
Solution / Fix
VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vulnerability
Solution:
Veritas has released an advisory (Document ID: 273419) with fix information to address this issue in Backup Exec 8.6 and Backup Exec 9.1. Please see the references for more information.
Veritas Software Backup Exec for Windows Servers 8.6
Veritas Software Backup Exec for Windows Servers 9.1
Solution:
Veritas has released an advisory (Document ID: 273419) with fix information to address this issue in Backup Exec 8.6 and Backup Exec 9.1. Please see the references for more information.
Veritas Software Backup Exec for Windows Servers 8.6
-
Veritas Software BENT86HF68_273422.exe
http://seer.support.veritas.com/docs/273422.htm
Veritas Software Backup Exec for Windows Servers 9.1
-
Veritas Software Be4691RHF40_273420.exe
http://seer.support.veritas.com/docs/273420.htm
References
VERITAS Backup Exec Agent Browser Remote Buffer Overflow Vulnerability
References:
References:
- Document ID: 273419 - stack-based buffer overflow vuln in Backup Exec 8 and 9 (Veritas Software)
- Metasploit Framework Exploits (Metasploit)
- Veritas Homepage (Veritas Software)
- iDEFENSE Security Advisory 12.16.04: Veritas Backup Exec Agent Browser (iDEFENSE Security Advisory
)