📄 3696.txt
字号:
Rule:--Sid:3696--Summary:This event is generated when an attempt is made to exploit adenial of service associated with a malformed Veritas BackupAgent request.--Impact:A successful attack can cause the Vertias Backup Agent serviceto crash.--Detailed Information:The Veritas Backup Agent Exec provides backup software. Certaincommunication is done via Network Data Management Protocol (NDMP).The NDMP protocol does not properly handle malformed requests thathave a non-zero error code value. When this condition isencountered, memory is not allocated, but processing continues asif it were. When an attempt is made to read from this buffer, anaccess violation occurs and the Backup Agent service is terminated.--Affected Systems: Veritas Software Backup Exec 9.0, 9.1, 10.0--Attack Scenarios:An attacker can send a malformed request to a Backup Agent server,causing it to crash.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Upgrade to the most current non-affected version of the product.--Contributors:Sourcefire Vulnerability Research TeamJudy Novak <judy.novak@sourcefire.com>--Additional ReferencesiDefense:http://www.idefense.com/application/poi/display?id=271&type=vulnerabilities--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -