VERITAS NetBackup Volume Manager Daemon Buffer Overflow

Critical Nessus Plugin ID 20182


Arbitrary code can be executed on the remote host.


The remote host is running a version of VERITAS NetBackup Volume Manager that is vulnerable to a remote buffer overflow. An attacker may exploit this flaw to execute arbitrary code on the remote host with the privileges of a local administrator or to disable the remote service remotely.

To exploit this flaw, an attacker would need to send a specially crafted packet to the remote service.


Plugin Details

Severity: Critical

ID: 20182

File Name: veritas_netbackup_vmd_overflow.nasl

Version: $Revision: 1.20 $

Type: remote

Agent: windows

Family: Windows

Published: 2005/11/11

Modified: 2012/12/10

Dependencies: 20181

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:symantec_veritas:netbackup

Required KB Items: VERITAS/NetBackupVolumeManager

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2005/11/08

Vulnerability Publication Date: 2005/11/08

Reference Information

CVE: CVE-2005-3116

BID: 15353

OSVDB: 20674