This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Veritas NetBackup: Overflow Vulns - updates available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

"When it rains, it pours"
—————————————————————
FYI… http://securityresponse.symantec.com/avcen…2006.03.27.html
Multiple Overflow Vulnerabilities in NetBackup Daemons
Severity - High (very configuration-dependent)
- http://support.veritas.com/docs/281521
27 March 2006
Symantec Security Advisory SYM06-006: Multiple overflow vulnerabilities exist in Veritas NetBackup ™ daemons that could potentially lead to execution of arbitrary code resulting in possible unauthorized, elevated privileged access to the targeted system…
NOTE: Security Packs (SPs) contain cumulative security fixes only. The Maintenance Packs (MPs and FPs) contain cumulative security fixes as well as additional product enhancements and technical updates…
Operating Systems:
- Windows 2000
Advanced Server, Advanced Server SP1, Advanced Server SP2, Advanced Server SP3, Advanced Server SP4, Datacenter Server SP1, Datacenter Server SP2, Datacenter Server SP3, Datacenter Server SP4, Server, Server SP1, Server SP2, Server SP3, Server SP4
- AIX
4.x, 5.1, 5.2, 5.3
- TRU64
5.1, 5.1A, 5.1B, 5.1B2
- HP-UX
11.0, 11.11
- IRIX
6.5.10, 6.5.11, 6.5.12, 6.5.13, 6.5.14, 6.5.15, 6.5.16, 6.5.17, 6.5.18, 6.5.19, 6.5.20, 6.5.21, 6.5.22, 6.5.23, 6.5.24, 6.5.25, 6.5.26
- Solaris
10, 2.6, 7.0, 8.0, 9.0
- Linux
RHAS 2.1, RHEL 3.0 (AS), RHEL 3.0 (ES), RHEL 4.0, RHEL 4.0 (IA64), RHEL 4.0 (x86_64), Red Flag Data Center Server 4.1, RedHat 6.1, RedHat 6.2, RedHat 7.0, RedHat 7.1, RedHat 7.2, RedHat 7.3, SLES 8, SLES 9, SLES 9 (IA64), SLES 9 (x86_64)
- Windows NT
4.0 Server SP6a
- Windows Server 2003
DataCenter, DataCenter (IA64), DataCenter SP1, DataCenter SP1(IA64), Enterprise (IA64), Enterprise SP1(IA64), Enterprise Server, Enterprise ServerSP1, Standard Server, Standard Server SP1, Storage Server…"
————————————————————–
FYI…

- http://secunia.com/advisories/19417/
"Release Date: 2006-03-28
Critical: Moderately critical
Impact: System access
Where: From local network
Solution Status: Vendor Patch
Software: VERITAS NetBackup Advanced Client 5.x
VERITAS Netbackup Advanced Client 6.x
VERITAS NetBackup BusinesServer 4.x
VERITAS NetBackup DataCenter 4.x
VERITAS NetBackup Enterprise Server 5.x
VERITAS NetBackup Enterprise Server 6.x
VERITAS NetBackup Server 5.x
VERITAS NetBackup Server 6.x …
Solution:
Apply patches.
http://support.veritas.com/docs/281521 …"

.