First published: Tue Sep 20 2005(Updated: )
Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec Veritas Storage Exec | =5.3_rev._2190r | |
Symantec Veritas Storagecentral | =5.2_rev._2190r |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2996 is considered critical due to its potential to allow remote code execution by attackers.
To fix CVE-2005-2996, apply the recommended hotfixes, specifically Hotfix 9 for Storage Exec 5.3 and Hot Fix 2 for StorageCentral 5.2.
CVE-2005-2996 affects Symantec Veritas Storage Exec 5.3 and StorageCentral 5.2.
CVE-2005-2996 is associated with heap-based and stack-based buffer overflow vulnerabilities.
Yes, CVE-2005-2996 can be exploited remotely through certain ActiveX controls.