Veritas Storage Exec Multiple Remote DCOM Buffer Overflow Vulnerabilities
BID:14801
Info
Veritas Storage Exec Multiple Remote DCOM Buffer Overflow Vulnerabilities
| Bugtraq ID: | 14801 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2996 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Mark Litchfield of NGS Research discovered these issues. |
| Vulnerable: |
Symantec VERITAS StorageCentral 5.2 rev. 322 Symantec VERITAS Storage Exec 5.3 rev. 2190R |
| Not Vulnerable: | |
Discussion
Veritas Storage Exec Multiple Remote DCOM Buffer Overflow Vulnerabilities
Veritas Storage Exec is susceptible to multiple remote buffer overflow vulnerabilities. These issues are due to the lack of proper bounds checking of user-supplied data prior to copying it to fixed size memory buffers.
These issues are located in multiple DCOM servers in the affected product. Both stack-based, and heap-based overflows are identified. By calling associated ActiveX controls, attackers may exploit these overflows to execute arbitrary machine code.
These vulnerabilities may be exploited by visiting malicious Web sites, or viewing HTML email containing malicious script code.
Veritas Storage Exec is susceptible to multiple remote buffer overflow vulnerabilities. These issues are due to the lack of proper bounds checking of user-supplied data prior to copying it to fixed size memory buffers.
These issues are located in multiple DCOM servers in the affected product. Both stack-based, and heap-based overflows are identified. By calling associated ActiveX controls, attackers may exploit these overflows to execute arbitrary machine code.
These vulnerabilities may be exploited by visiting malicious Web sites, or viewing HTML email containing malicious script code.
Exploit / POC
Veritas Storage Exec Multiple Remote DCOM Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Veritas Storage Exec Multiple Remote DCOM Buffer Overflow Vulnerabilities
Solution:
Symantec has released advisory SYM05-014, along with fixes to address these issues. Please see the referenced advisory for further information.
Symantec VERITAS StorageCentral 5.2 rev. 322
Symantec VERITAS Storage Exec 5.3 rev. 2190R
Solution:
Symantec has released advisory SYM05-014, along with fixes to address these issues. Please see the referenced advisory for further information.
Symantec VERITAS StorageCentral 5.2 rev. 322
-
Symantec VERITAS StorageCentral (tm) 5.2 rev 322 - Hotfix Q323003.ism Hot Fix 2
http://support.veritas.com/docs/277567
Symantec VERITAS Storage Exec 5.3 rev. 2190R
-
Symantec VERITAS Storage Exec (tm) 5.3 rev 2190R - Hotfix 9
http://support.veritas.com/docs/277566
References
Veritas Storage Exec Multiple Remote DCOM Buffer Overflow Vulnerabilities
References:
References:
- SYM05-014 - VERITAS Storage Exec DCOM Server Buffer Overflows (Symantec)
- VERITAS Storage Exec Home Page (Symantec)