|
|
|
|
| |
Credit:
The information has been provided by ZDI-06-049.
The original article can be found at:
http://www.zerodayinitiative.com/advisories/ZDI-06-049.html
|
| |
Vulnerable Systems:
* Veritas NetBackup 6.0 prior to MP4
* Veritas NetBackup 5.1 prior to MP6
* Veritas NetBackup 5.0 prior to MP7
CVE Information:
CVE-2006-6222
The specific flaw exists within bpcd.exe during the parsing of overly long requests to a NetBackup Master/Media Server. Communications to this process are prefixed with a length, which, if malformed can result in a stack based buffer overflow. Exploitation of this vulnerability can lead to complete system compromise.
Vendor Status:
Symantec has issued an update to correct this vulnerability. More details can be found at:
http://www.symantec.com/avcenter/security/Content/2006.12.13a.html
Disclosure Timeline:
* 2006.08.14 - Vulnerability reported to vendor
* 2006.11.20 - Digital Vaccine released to TippingPoint customers
* 2006.12.13 - Coordinated public release of advisory
|
|
|
|
|