Symantec Storage Foundation for Windows Scheduler Service Denial of Service Vulnerability
BID:27440
Info
Symantec Storage Foundation for Windows Scheduler Service Denial of Service Vulnerability
| Bugtraq ID: | 27440 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4516 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2008 12:00AM |
| Updated: | Feb 21 2008 06:43PM |
| Credit: | iDefense Labs is credited with discovering this vulnerability. |
| Vulnerable: |
Symantec Storage Foundation for Windows 5.0 |
| Not Vulnerable: |
Symantec Storage Foundation for Windows 4.2RP2 Symantec Storage Foundation for Windows 4.2RP1 Symantec Storage Foundation for Windows 4.2 Symantec Storage Foundation for Windows 4.1RP1 Symantec Storage Foundation for Windows 4.1 Symantec Storage Foundation for Windows 3.1 |
Discussion
Symantec Storage Foundation for Windows Scheduler Service Denial of Service Vulnerability
Symantec Storage Foundation for Windows scheduler service is prone to a denial-of-service vulnerability because it fails to validate user-supplied input.
Attackers can exploit this issue by transmitting specially crafted packets to the scheduler service to crash the application, denying service to legitimate users.
This issue affects Storage Foundation 5.0 for Windows.
Symantec Storage Foundation for Windows scheduler service is prone to a denial-of-service vulnerability because it fails to validate user-supplied input.
Attackers can exploit this issue by transmitting specially crafted packets to the scheduler service to crash the application, denying service to legitimate users.
This issue affects Storage Foundation 5.0 for Windows.
Exploit / POC
Symantec Storage Foundation for Windows Scheduler Service Denial of Service Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Symantec Storage Foundation for Windows Scheduler Service Denial of Service Vulnerability
Solution:
Symantec has released fixes to address this issue. Please see the references for more information.
Solution:
Symantec has released fixes to address this issue. Please see the references for more information.
References
Symantec Storage Foundation for Windows Scheduler Service Denial of Service Vulnerability
References:
References:
- Storage Foundation for Windows Product Page (Symantec)
- iDefense Security Advisory 02.20.08: Symantec Veritas Storage Foundation Schedul (iDefense Labs
) - iDefense Security Advisory 02.20.08: Symantec Veritas Storage Foundation Schedu (iDefense Labs)
- SYM08-004 Veritas Storage Foundation for Windows by Symantec: Denial of Service (Symantec)