Get a Pentest and security assessment of your IT network.

Advisories

iDEFENSE Security Advisory 2007-07-11.1

iDefense Security Advisory 07.11.07 – Remote exploitation of a heap overflow vulnerability in Symantec Backup Exec could allow an unauthenticated attacker to create a denial of service condition or potentially execute arbitrary code. The flaw specifically exists within the RPC server that listens on TCP port 6106. When handling requests using the “ncacn_ip_tcp” protocol, the service will copy a user supplied amount of data into a fixed-size heap buffer. iDefense confirmed the existence of this vulnerability in Symantec Backup Exec 10d with all current hot-fixes and service packs applied. Other versions are suspected to be vulnerable.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57668/07.11.07-1.txt

Source: https://packetstormsecurity.com/files/57668/iDEFENSE-Security-Advisory-2007-07-11.1.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1