CVE-2011-0547: Buffer Overflow
Multiple integer overflows in vxsvc.exe in the Veritas Enterprise Administrator service in Symantec Veritas Storage Foundation 5.1 and earlier, Veritas Storage Foundation Cluster File System (SFCFS) 5.1 and earlier, Veritas Storage Foundation Cluster File System Enterprise for Oracle RAC (SFCFSORAC) 5.1 and earlier, Veritas Dynamic Multi-Pathing (DMP) 5.1, and NetBackup PureDisk 6.5.x through 6.6.1.x allow remote attackers to execute arbitrary code via (1) a crafted Unicode string, related to the vxveautil.valuebinaryunpack function; (2) a crafted ASCII string, related to the vxveautil.valuebinaryunpack function; or (3) a crafted value, related to the vxveautil.kvbinaryunpack function, leading to a buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0547?
CVE-2011-0547 is rated as high severity due to its potential for remote code execution.
How do I fix CVE-2011-0547?
To fix CVE-2011-0547, update the affected Symantec software to the latest version provided by the vendor.
What products are affected by CVE-2011-0547?
CVE-2011-0547 affects multiple versions of Symantec Veritas Storage Foundation, Veritas Dynamic Multi-Pathing, and NetBackup PureDisk.
What is an integer overflow vulnerability in CVE-2011-0547?
CVE-2011-0547 describes integer overflow vulnerabilities that can lead to buffer overflows, allowing potential code execution.
Has CVE-2011-0547 been exploited in the wild?
There have been reports of CVE-2011-0547 being exploited in the wild, emphasizing the importance of applying available patches.