This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Symantec Backup Exec multiple vulns - update available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Symantec Backup Exec vuln - update available
- http://secunia.com/advisories/26032/
Release Date: 2007-07-11
Critical: Moderately critical
Impact: DoS, System access
Where: From local network
Solution Status: Vendor Patch
…The vulnerability is reported in the following versions:
* Backup Exec for Windows Servers version 10.0 build 10.0.5484
* Backup Exec for Windows Servers version 10.0 build 10.0.5520
* Backup Exec for Windows Servers version 10d build 10.1.5629
* Backup Exec for Windows Servers version 11d build 11.0.6235
* Backup Exec for Windows Servers version 11d build 11.0.7170
Solution: Apply the hotfix:
http://support.veritas.com/docs/289283
Last Updated: July 11 2007 01:02 PM GMT …
Original Advisory:
http://securityresponse.symantec.com/avcen…007.07.11a.html
Severity: High
Remote Access: Yes …

.
FYI…

Symantec Backup Exec multiple vulns - hotfix available
- http://secunia.com/advisories/27885/
Release Date: 2008-02-29
Critical: Moderately critical
Impact: Manipulation of data, System access
Where: From remote
Solution Status: Vendor Patch
Software: Symantec Backup Exec for Windows Servers 11.x, 12.x
…Successful exploitation of the vulnerabilities allow execution of arbitrary code.
The vulnerabilities are confirmed in pvcalendar.ocx version 10.0.0.17 included in Symantec Backup Exec for Windows Servers version 11d build 7170, and affects the following versions:
* Symantec Backup Exec for Windows Server 11d build 11.0.6235
* Symantec Backup Exec for Windows Server 11d build 11.0.7170
* Symantec Backup Exec for Windows Server 12.0 build 12.0.1364
Solution: Apply hotfix.
http://seer.entsupport.symantec.com/docs/300471.htm …
Original Advisory: SYM08-007:
http://www.symantec.com/avcenter/security/…2008.02.28.html …
"…Vulnerabilities were reported in an ActiveX control…"

:ph34r:
FYI…

Symantec Backup Exec vuln - SYM08-013
- http://secunia.com/advisories/30432/
Release Date: 2008-05-29
Critical: Moderately critical
Impact: Exposure of sensitive information, System access
Solution Status: Vendor Patch
Software: Symantec Backup Exec System Recovery 7.x, Symantec Backup Exec System Recovery 8.x
…unauthorized access to the vulnerable system via directory traversal attacks.
The vulnerability is reported in versions 7.x and 8.x.
Solution: Update to version 7.0.4 or 8.0.2.
https://fileconnect.symantec.com/
Original Advisory: SYM08-013:
- http://securityresponse.symantec.com/avcen…008.05.28c.html
SYM08-013 - May 28, 2008
Symantec Backup Exec System Recovery Manager - Directory Traversal Vulnerability
Remote Access: Yes…

:ph34r: