CVE-2005-2996: Buffer Overflow
Published Sep 20, 2005
·Updated
Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls.
Affected Software
2 affected components
Symantec Veritas Storage Exec=5.3_rev._2190r
Symantec Veritas Storagecentral=5.2_rev._2190r
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2996?
CVE-2005-2996 is considered critical due to its potential to allow remote code execution by attackers.
2
How do I fix CVE-2005-2996?
To fix CVE-2005-2996, apply the recommended hotfixes, specifically Hotfix 9 for Storage Exec 5.3 and Hot Fix 2 for StorageCentral 5.2.
3
Which products are affected by CVE-2005-2996?
CVE-2005-2996 affects Symantec Veritas Storage Exec 5.3 and StorageCentral 5.2.
4
What types of vulnerabilities are associated with CVE-2005-2996?
CVE-2005-2996 is associated with heap-based and stack-based buffer overflow vulnerabilities.
5
Can CVE-2005-2996 be exploited remotely?
Yes, CVE-2005-2996 can be exploited remotely through certain ActiveX controls.