VERITAS NetBackup Volume Manager Daemon Buffer Overflow Vulnerability
BID:15353
Info
VERITAS NetBackup Volume Manager Daemon Buffer Overflow Vulnerability
| Bugtraq ID: | 15353 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3116 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2005 12:00AM |
| Updated: | Jan 16 2006 02:40PM |
| Credit: | Discovery is credited to an anonymous source. |
| Vulnerable: |
Veritas Software NetBackup Server 5.1 Veritas Software NetBackup Server 5.0 Veritas Software NetBackup Enterprise Server 5.1 Veritas Software NetBackup Enterprise Server 5.0 Veritas Software NetBackup Client 5.1 Veritas Software NetBackup Client 5.0 |
| Not Vulnerable: | |
Discussion
VERITAS NetBackup Volume Manager Daemon Buffer Overflow Vulnerability
VERITAS NetBackup is prone to a buffer overflow in the Volume Manager Daemon. Successful exploitation could result in a denial of service or arbitrary code execution.
This issue only affects NetBackup 5.0 and 5.1.
VERITAS NetBackup is prone to a buffer overflow in the Volume Manager Daemon. Successful exploitation could result in a denial of service or arbitrary code execution.
This issue only affects NetBackup 5.0 and 5.1.
Exploit / POC
VERITAS NetBackup Volume Manager Daemon Buffer Overflow Vulnerability
Exploit code has been released by Patrick Thomassen.
Exploit code has been released by Patrick Thomassen.
Solution / Fix
VERITAS NetBackup Volume Manager Daemon Buffer Overflow Vulnerability
Solution:
Fixes are available:
Veritas Software NetBackup Client 5.0
Veritas Software NetBackup Server 5.0
Veritas Software NetBackup Enterprise Server 5.0
Veritas Software NetBackup Server 5.1
Veritas Software NetBackup Client 5.1
Veritas Software NetBackup Enterprise Server 5.1
Solution:
Fixes are available:
Veritas Software NetBackup Client 5.0
-
VERITAS Software Cumulative Security Pack NB_50_5S2
http://support.veritas.com/menu_ddProduct_NBUESVR_view_DOWNLOAD.htm
Veritas Software NetBackup Server 5.0
-
VERITAS Software Cumulative Security Pack NB_50_5S2
http://support.veritas.com/menu_ddProduct_NBUESVR_view_DOWNLOAD.htm
Veritas Software NetBackup Enterprise Server 5.0
-
VERITAS Software Cumulative Security Pack NB_50_5S2
http://support.veritas.com/menu_ddProduct_NBUESVR_view_DOWNLOAD.htm
Veritas Software NetBackup Server 5.1
-
VERITAS Software Cumulative Security Pack NB_51_3AS2
http://support.veritas.com/menu_ddProduct_NBUESVR_view_DOWNLOAD.htm
Veritas Software NetBackup Client 5.1
-
VERITAS Software Cumulative Security Pack NB_51_3AS2
http://support.veritas.com/menu_ddProduct_NBUESVR_view_DOWNLOAD.htm
Veritas Software NetBackup Enterprise Server 5.1
-
VERITAS Software Cumulative Security Pack NB_51_3AS2
http://support.veritas.com/menu_ddProduct_NBUESVR_view_DOWNLOAD.htm
References
VERITAS NetBackup Volume Manager Daemon Buffer Overflow Vulnerability
References:
References:
- Stack Overflow in Veritas Netbackup Enterprise Server (iDEFENSE)
- Veritas Homepage (Veritas Software)
- VERITAS NetBackup 5.x: Buffer Overflow in Shared Library used by Volume Manager (VERITAS Software)