VERITAS Backup Exec Agent for Windows CONNECT_CLIENT_AUTH Remote Overflow

This script is Copyright (C) 2005-2011 Tenable Network Security, Inc.


Synopsis :

Arbitrary code can be executed on the remote host.

Description :

The remote host is running a version of VERITAS Backup Exec Agent
which is vulnerable to a remote buffer overflow. An attacker may
exploit this flaw to execute arbitrary code on the remote host or to
disable this service remotely.

To exploit this flaw, an attacker would need to send a specially
crafted packet to the remote service.

Solution :

http://seer.support.veritas.com/docs/276604.htm

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.3
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows

Nessus Plugin ID: 18551 ()

Bugtraq ID: 14019
14021
14022

CVE ID: CVE-2005-0773

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now