First published: Sat Jun 18 2005(Updated: )
Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Veritas Backup Exec | =10.0_rev.5484_sp1 | |
Symantec Veritas Backup Exec | =9.1.1151.1 | |
Symantec Veritas Backup Exec | =10.0_rev.5484 | |
Symantec Veritas Backup Exec | =9.0_rev.4367_sp1 | |
Symantec Veritas Backup Exec | =9.1.1067.3 | |
Symantec Veritas Backup Exec | =9.0.4202 | |
Symantec Veritas Backup Exec | =9.1.1152.4 | |
Symantec Veritas Backup Exec | =9.0.4174 | |
Symantec Veritas Backup Exec | =9.1_rev.4691_sp2 | |
Symantec Veritas Backup Exec | =9.1.306 | |
Symantec Veritas Backup Exec | =9.0_rev.4454 | |
Symantec Veritas Backup Exec | =9.1.1127.1 | |
Symantec Veritas Backup Exec | =9.1.1067.2 | |
Symantec Veritas Backup Exec | =9.1.1154 | |
Symantec Veritas Backup Exec | =9.0.4019 | |
Symantec Veritas Backup Exec | =9.0_rev.4367 | |
Symantec Veritas Backup Exec | =9.0.4170 | |
Symantec Veritas Backup Exec | =9.1.307 | |
Symantec Veritas Backup Exec | =9.1.1152 | |
Symantec Veritas Backup Exec | =9.0_rev.4454_sp1 | |
Symantec Veritas Backup Exec | =9.1_rev.4691 | |
Symantec Veritas Backup Exec | =9.0.4172 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0773 is classified as critical due to its potential to allow remote attackers to execute arbitrary code.
To resolve CVE-2005-0773, users should upgrade to a patched version of Symantec Veritas Backup Exec as specified by the vendor.
CVE-2005-0773 affects Symantec Veritas Backup Exec versions 9.0 through 10.0 for Windows and specific versions for Netware.
Yes, CVE-2005-0773 can be exploited remotely through a crafted CONNECT_CLIENT_AUTH request.
Successful exploitation of CVE-2005-0773 can lead to unauthorized remote code execution, compromising the integrity and confidentiality of the affected system.