First published: Sat Dec 31 2005(Updated: )
Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWorker | =7.1.1 | |
NetWorker | =7.1.2 | |
NetWorker | =7.1.3 | |
NetWorker | =7.2 | |
NetWorker | =7.2.1 | |
NetWorker | =7.2_build172 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3658 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2005-3658, upgrade EMC Legato NetWorker to version 7.1.4 or later for 7.1.x, and to version 7.2.1.Build.314 or later for 7.2.x.
CVE-2005-3658 affects EMC Legato NetWorker 7.1.x before 7.1.4, 7.2.x before 7.2.1.Build.314, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup Software 7.1 through 7.2L.
Yes, CVE-2005-3658 can be exploited by remote attackers, allowing them to execute arbitrary code.
CVE-2005-3658 is categorized as a heap-based buffer overflow vulnerability.