Symantec Backup Exec Scheduler ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
BID:26904
Info
Symantec Backup Exec Scheduler ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26904 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6016 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2008 12:00AM |
| Updated: | Sep 24 2008 11:59PM |
| Credit: | JJ Reyes of Secunia Research discovered these issues. |
| Vulnerable: |
Symantec Veritas NetBackup Server 6.5 Symantec Veritas NetBackup Server 6.0 Symantec Veritas NetBackup Server 5.1 Symantec Veritas NetBackup Enterprise Server 6.5 Symantec Veritas NetBackup Enterprise Server 6.0 Symantec Veritas NetBackup Enterprise Server 5.1 Symantec Backup Exec for Windows Servers 12.0 Symantec Backup Exec for Windows Servers 11d |
| Not Vulnerable: |
Symantec Veritas NetBackup Server 6.5.2 Symantec Veritas NetBackup Server 6.0 MP7 Symantec Veritas NetBackup Server 5.1 MP7 Symantec Veritas NetBackup Enterprise Server 6.5.2 Symantec Veritas NetBackup Enterprise Server 6.0 MP7 Symantec Veritas NetBackup Enterprise Server 5.1 MP7 |
Discussion
Symantec Backup Exec Scheduler ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
An ActiveX control in the scheduler component of Symantec Backup Exec is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
An ActiveX control in the scheduler component of Symantec Backup Exec is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
Symantec Backup Exec Scheduler ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE (May 8, 2008): The Symantec Threat Analysis Team has observed active exploits in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
UPDATE (May 8, 2008): The Symantec Threat Analysis Team has observed active exploits in the wild.
The following exploit is available:
Solution / Fix
Symantec Backup Exec Scheduler ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
Solution:
Symantec released an advisory and fixes to address these issues. Please see the references for more information.
Symantec Backup Exec for Windows Servers 11d
Symantec Backup Exec for Windows Servers 12.0
Solution:
Symantec released an advisory and fixes to address these issues. Please see the references for more information.
Symantec Backup Exec for Windows Servers 11d
-
Symantec be6235RHF31_32bit_300630.exe
http://support.veritas.com/docs/300630 -
Symantec be6235RHF31_x64bit_300631.exe
http://support.veritas.com/docs/300631 -
Symantec be7170RHF39_32bit_300627.exe
http://support.veritas.com/docs/300627 -
Symantec be7170RHF39_x64bit_300628.exe
http://support.veritas.com/docs/300628
Symantec Backup Exec for Windows Servers 12.0
-
Symantec be1364R300287_32bit_300632.exe
http://support.veritas.com/docs/300632 -
Symantec be1364R300287_x64bit_300633.exe
http://support.veritas.com/docs/300633
References
Symantec Backup Exec Scheduler ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Symantec Backup Exec Homepage (Symantec )
- SYM08-007 Symantec Backup Exec and NetBackup for Windows Servers Multiple Vulner (Symantec)
- Symantec Backup Exec Calendar Control Multiple Vulnerabilities (Secunia Research)