CVE-2007-3618: Buffer Overflow
Published Aug 21, 2007
·Updated
Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute arbitrary code via a (1) poll or (2) kill request with a "long invalid subcmd."
Affected Software
5 affected components
EMC Legato NetWorker=7.0
EMC Legato NetWorker=7.2
EMC Legato NetWorker=7.3.2
EMC Legato NetWorker=7.1.3
EMC Legato NetWorker=7.2.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 21, 2007
CVE Published
09:17 PM
Aug 22, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-3618?
CVE-2007-3618 is considered to have a high severity due to its potential for remote code execution.
2
How do I fix CVE-2007-3618?
To fix CVE-2007-3618, you should upgrade to a patched version of EMC Legato NetWorker that addresses the vulnerability.
3
What versions of EMC Legato NetWorker are affected by CVE-2007-3618?
CVE-2007-3618 affects EMC Legato NetWorker versions 7.0, 7.1.3, 7.2, 7.2.1, and 7.3.2.
4
Can CVE-2007-3618 be exploited locally?
CVE-2007-3618 is primarily a remote vulnerability, allowing attackers to execute arbitrary code from a remote location.
5
What type of vulnerability is CVE-2007-3618?
CVE-2007-3618 is a stack-based buffer overflow vulnerability in the NetWorker Remote Exec Service.