Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
|
|
|
|
|
|
|
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
|
|
|
|
Become a Partner and License Our Database or Notification Service
|
|
|
|
|
|
|
|
|
|
|
|
|
|
VERITAS Backup Exec Buffer Overflow in Processing Registration Requests Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1012597
|
|
SecurityTracker URL: http://securitytracker.com/id?1012597
|
|
CVE Reference: CAN-2004-1172
(Links to External Site)
|
Updated: Dec 16 2004
|
Original Entry Date: Dec 16 2004
|
Impact: Execution of arbitrary code via network, Root access via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 8.x, 9.x
|
Description: A buffer overflow vulenerability was reported in Backup Exec. A remote user may be able to execute arbitrary code.
The vendor reported that there is a stack-based overflow in the processing of registration requests. A remote user can supply specially
crafted data to execute arbitrary code with the privileges of one of the VERITAS Backup Exec service processes (typically a domain
administrative account).
iDEFENSE reported that an overly long hostname component of the registration request can trigger the
flaw.
The vendor was notified on November 2, 2004.
|
Impact: A remote user can execute arbitrary code with the privileges of one of the VERITAS Backup Exec service processes.
|
Solution: The vendor has issued the following hotfixes:
For Backup Exec 8.6 Build 3878:
BENT86HF68_273422.exe 8.60.3878 Hotfix 68
http://support.veritas.com/docs/273422
Fo
r Backup Exec 9.1 Build 4691 Service Pack 1:
Be4691RHF40_273420.exe 9.1.4691 Hotfix 40
http://support.veritas.com/docs/273420
The
vendor has also described some workaround procedures in their advisory, available at:
http://seer.support.veritas.com/docs/273419.htm
|
Vendor URL: seer.support.veritas.com/docs/273419.htm (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Windows (NT), Windows (2000), Windows (2003)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 16 Dec 2004 09:43:21 -0500
Subject: http://seer.support.veritas.com/docs/273419.htm
|
Document ID: 273419
http://support.veritas.com/docs/273419
Remote exploitation of a stack-based buffer overflow vulnerability in Backup Exec 8.x
and 9.x may allow the unauthorized execution of arbitrary code.
Details:
The vulnerability specifically exists within the function responsible for receiving
and parsing registration requests. The issue allows a remote attacker to execute
arbitrary code under the privileges of one of the VERITAS Backup Exec (tm) service
processes, which is usually a domain administrative account.
A hotfix is available for the following versions of Backup Exec:
Backup Exec 8.6 installations should have the following hotfix applied:
BENT86HF68_273422.exe 8.60.3878 Hotfix 68 - Backup Exec (buffer overflow creates a security hole in a gent browser)
http://support.veritas.com/docs/273422
Note: Backup Exec 8.x installations should be upgraded to Backup Exec 8.6 Build 3878 prior to the ins tallation of the hotfix.
Backup Exec 9.1 installations should have the following hotfix applied:
Be4691RHF40_273420.exe 9.1.4691 Hotfix 40 - Backup Exec (buffer overflow creates a
security hole in agent browser)
http://support.veritas.com/docs/273420
Note: Backup Exec 9.0 and 9.1 installations should be upgraded to Backup Exec 9.1
Build 4691 Service Pack 1 prior to the installation of the hotfix.
Workaround for all Backup Exec versions:
To avoid this issue in any version of Backup Exec, a firewall can be used to restrict
incoming connections to trusted workstations running Backup Exec software.
Note: VERITAS Technical Services recommends that Backup Exec installations are always
kept at the latest version, build, and hotfix level available. It is also recommended
that a full backup is performed prior to and after any changes are made to a software
environment. If you have any questions or concerns about this issue, please contact
VERITAS Technical Services.
VERITAS Software has acknowledged that the above-mentioned issue may be present in
earlier versions of the product which are no longer supported. There are no plans to
address this issue by way of a patch or hotfix in any end-of-life versions of the
product at the present time. The issue has been addressed in all supported versions
of the product specified at the end of this article. If you have an unsupported
version of the product, you will have to move to a supported version of the product
to apply the patch or implement the workaround mentioned above.
Related Documents:
241035: VERITAS Backup Exec (tm) 8.6 for Windows NT build 3878 (Intel) (English)
http://support.veritas.com/docs/241035
264658: Q118478.BEWS.91.4691.1_264658.zip VERITAS Backup Exec (tm) 9.1 for Windows Servers revision 4691.1 (Single .ZIP download)
http://support.veritas.com/docs/264658
267180: Be4691RSP1_267180.exe VERITAS Backup Exec (tm) 9.1 for Windows Servers revision 4691 - Servi ce Pack 1
http://support.veritas.com/docs/267180
Supplemental Material:
System: Ref.# Description
ETrack: 275793 BEWS: Buffer overflow creates a security hole in Agent Browser (BEWS 8.6)
ETrack: 275738 BEWS: Buffer overflow creates a security hole in Agent Browser (BEWS 9.1)
Products Applied:
Backup Exec for Windows Servers 8.0, 8.5, 8.6, 9.0, 9.1
Last Updated: December 15 2004 04:41 PM GMT
Expires on: 12-15-2005
Subscribe Via E-Mail IconSubscribe to this document
Subjects:
Backup Exec for Windows Servers
Application: Alert, Troubleshooting
Publishing Status: Techalert
Languages:
English (US)
Operating Systems:
Windows 2000
Advanced Server, Advanced Server Windows Powered, Datacenter Server, Professional,
SAK, Server, Server Windows Powered
Windows NT
4.0 Server SP6a, 4.0 Workstation SP6a
Windows NT Small Business Server
2000, 4.5
Windows XP
Home 5.1, Pro 5.1
Windows Server 2003
DataCenter, Enterprise Server, Standard Server, Storage Server, Web Server
Windows Small Business Server 2003
Premium Edition, Standard Edition
|
|
Go to the Top of This SecurityTracker Archive Page
|