Symantec Veritas Enterprise Administrator Service Multiple Buffer Overflow Vulnerabilities
10 Apr. 2011
Summary
This allow remote attackers to execute arbitrary code via (1) a crafted Unicode string, related to the vxveautil.value_binary_unpack function; (2) a crafted ASCII string, related to the vxveautil.value_binary_unpack function; or (3) a crafted value, related to the vxveautil.kv_binary_unpack function, leading to a buffer overflow.
Vulnerable Systems:
* Symantec Veritas Storage Foundation 5.1 ,
* Veritas Storage Foundation Cluster File System (SFCFS) 5.1 ,
* Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 ,
* Veritas Dynamic Multi-Pathing (DMP) 5.1,
* NetBackup PureDisk 6.5.x through 6.6.1.x
The Symantec Veritas Enterprise Administrator service ('vxsvc.exe') is prone to multiple buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Attackers may leverage these issues to execute arbitrary code with administrative privileges on the affected system. Failed attacks will cause denial-of-service conditions.
Vendor Status:
Symantec as issued an update for this vulnerablity