📄 3695.txt
字号:
Rule:--Sid:--Summary:This event is generated when an attempt is made to exploit a vulnerabilityassociated with Veritas Backup Agent authentication.--Impact:Serious. Execution of arbitrary commands may be possible.--Detailed Information:A vulnerability exists in Veritas Backup Agent authentication software.This software uses Network Data Management Protocol (NDMP) tocommunicate between clients and servers. Authentication is required tosuccessfully connect. If an overly long password value is supplied duringauthentication, a buffer overflow may occur than can present an attackerwith the opportunity to execute code of their choosing.--Affected Systems: Backup Exec 10.0 for Windows Servers rev. 5484 Backup Exec 9.1 for Windows Servers rev. 4691 Backup Exec 9.0 for Windows Servers rev. 4454 Backup Exec 9.0 for Windows Servers rev. 4367 Backup Exec 9.1.307 for NetWare Servers Backup Exec 9.1.306 for NetWare Servers Backup Exec 9.1.1154 for NetWare Servers Backup Exec 9.1.1152.4 for NetWare Servers Backup Exec 9.1.1152 for NetWare Servers Backup Exec 9.1.1151.1 for NetWare Servers Backup Exec 9.1.1127.1 for NetWare Servers Backup Exec 9.1.1067.3 for NetWare Servers Backup Exec 9.1.1067.2 for NetWare Servers Backup Exec 9.0.4202 for NetWare Servers Backup Exec 9.0.4174 for NetWare Servers Backup Exec 9.0.4172 for NetWare Servers Backup Exec 9.0.4170 for NetWare Servers Backup Exec 9.0.4019 for NetWare Servers--Attack Scenarios:An attacker can send an overly long password, causing a bufferoverflow and the subsequent execution of arbitrary code ona vulnerable host.--Ease of Attack:Simple. Exploit scripts are freely available.--False Positives:None known.--False Negatives:None known.--Corrective Action:Upgrade to the most current nonaffected version of the software.--Contributors:Sourcefire Vulnerability Research TeamJudy Novak <judy.novak@sourcefire.com>--Additional References:iDefense:http://www.idefense.com/application/poi/display?id=272&type=vulnerabilities--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -