Vulnerabilities > CVE-2006-4128 - Unspecified vulnerability in Symantec Veritas Backup Exec
Summary
Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Backup Exec Continuous Protection Server Remote Agent for Windows Server 10.1 (builds 10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, and 10.1.327.401), and Backup Exec for Windows Server and Remote Agent 9.1 (build 9.1.4691), 10.0 (builds 10.0.5484 and 10.0.5520), and 10.1 (build 10.1.5629) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RPC message.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | SYMANTEC_BACKUP_EXEC_RPC_HEAP_OVERFLOWS.NASL |
description | The Windows remote host contains Symantec Backup Exec for Windows Server or Backup Exec Continuous Protection Server, a commercial backup product. The version of the software installed on the remote host is affected by multiple heap overflow conditions involving specially crafted calls to its RPC interfaces. An authenticated, remote attacker can exploit these issues to crash the affected application or execute arbitrary code with elevated privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22226 |
published | 2006-08-16 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22226 |
title | Symantec Backup Exec Multiple Heap Overflow RCE (SYM06-014) |
code |
|
References
- http://secunia.com/advisories/21472
- http://secunia.com/advisories/21472
- http://securityreason.com/securityalert/1380
- http://securityreason.com/securityalert/1380
- http://securityresponse.symantec.com/avcenter/security/Content/2006.08.11.html
- http://securityresponse.symantec.com/avcenter/security/Content/2006.08.11.html
- http://securitytracker.com/id?1016683
- http://securitytracker.com/id?1016683
- http://seer.entsupport.symantec.com/docs/284623.htm
- http://seer.entsupport.symantec.com/docs/284623.htm
- http://www.kb.cert.org/vuls/id/647796
- http://www.kb.cert.org/vuls/id/647796
- http://www.securityfocus.com/archive/1/443037/100/0/threaded
- http://www.securityfocus.com/archive/1/443037/100/0/threaded
- http://www.securityfocus.com/bid/19479
- http://www.securityfocus.com/bid/19479
- http://www.vupen.com/english/advisories/2006/3266
- http://www.vupen.com/english/advisories/2006/3266
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28336
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28336