This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Multiple VERITAS Backup vulns - updates available

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Veritas Backup Exec/NetBackup Request Packet Denial Of Service Vulnerability
2005-06-22
http://www.securityfocus.com/bid/14019/info

Veritas Backup Exec Remote Agent for Windows Servers Authentication Buffer Overflow Vulnerability
2005-06-22
http://www.securityfocus.com/bid/14022/info

Veritas Backup Exec Remote Agent for Windows Servers Privilege Escalation Vulnerability
2005-06-22
http://www.securityfocus.com/bid/14026/info

Veritas Backup Exec Remote Agent Null Pointer Dereference Denial Of Service Vulnerability
2005-06-22
http://www.securityfocus.com/bid/14021/info

Veritas Backup Exec Admin Plus Pack Option Remote Heap Overflow Vulnerability
2005-06-22
http://www.securityfocus.com/bid/14023/info

Veritas Backup Exec Server Remote Registry Access Vulnerability
2005-06-22
http://www.securityfocus.com/bid/14020/info

Veritas Backup Exec Web Administration Console Remote Buffer Overflow Vulnerability
2005-06-22
http://www.securityfocus.com/bid/14025/info

Links to the patches that fix these issues are listed on the "References" tab for each item.

:ph34r:
FYI…

- http://isc.sans.org/diary.php?date=2005-06-25
Updated June 25th 2005 20:24 UTC
"New Veritas Exploit
We received some reports about spikes on port 10000. The main reason for that is the release of the exploit for Veritas, and used by the Metasploit Framework…
An excerpt of the exploit is below:
'RHOST' => [1, 'ADDR', 'The target address'],
'RPORT' => [1, 'PORT', 'The target port', 10000],
One of our readers also sent an interesting note about the usage of the new Veritas Exploit:"…So, it seems this exploit is crashing the service listening on port 10000. If sysadmins know they have backup exec installed and they scan the system they will see port 6101 and 10000 normally. After the exploit it will show only the port 6101 still listening."

- http://isc.sans.org/port_details.php?port=10000

:ph34r:
FYI…

- http://www.techweb.com/wire/security/164903931
June 29, 2005
"One of the seven vulnerabilities recently found in various Veritas backup components is under attack… "This is indeed the result of a malicious IRC-based bot program, known as W32.Toxbot," Symantec researchers said in the report issued Thursday. Toxbot, which was first discovered in March, can also use various Microsoft vulnerabilities, including those in SQL Server, DCOM, and LSASS, the trio that spawned Slammer, MSBlast, and Sasser, respectively. "The DeepSight team strongly encourages network and system administrators to take immediate action to patch or mitigate the threat in the vulnerability"…"
- http://www.symantec.com/avcenter/venc/data/w32.toxbot.html
Last Updated on: June 28, 2005
"W32.Toxbot is a worm that opens an IRC back door on the compromised computer and spreads by exploiting vulnerabilities."

:ph34r:
FYI…

VERITAS NetBackup Vulnerability - remote (NEW)
- http://isc.sans.org/diary.php?storyid=755
Last Updated: 2005-10-12 11:50
"Veritas has announced a vulnerability, Document ID: 279085, describing a remotely exploitable "format string overflow vulnerability in the Java authentication service, bpjava-msvc, running on NetBackup servers and clients" that is "known to affect the application server for the NetBackup Java GUI."
"The vulnerable daemon listens on port 13722 on both NetBackup servers and clients."
Affected products:
NetBackup 4.5, all versions, all platforms.
NetBackup 5.0, all versions, all platforms.
NetBackup 5.1, all versions, all platforms.
NetBackup 6.0, all versions, all platforms.
Their suggested workaround; Block external network access on TCP port 13722 …"
>>> http://seer.support.veritas.com/docs/279085.htm
Last Updated: October 11 2005

:ph34r:
FYI…

VERITAS NetBackup ™ Enterprise Server/Server 5.0 and 5.1 BO
- http://isc.sans.org/diary.php?storyid=832
Published: 2005-11-08,
Last Updated: 2005-11-08 23:26:49 UTC
"Symantec/Veritas has issued Advisory SYM05-024: Exploitation of a buffer overflow vulnerability in VERITAS NetBackup ™ Enterprise Server/Server 5.0 and 5.1 could potentially lead to a remote Denial Of Service or remote code execution. The vulnerability was responsibly reported to Symantec by iDefense Labs."
>>> http://seer.support.veritas.com/docs/279553.htm

:ph34r: