First published: Sun Aug 04 2013(Updated: )
Heap-based buffer overflow in the utility program in the Linux agent in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote attackers to cause a denial of service (agent crash) or possibly execute arbitrary code via unspecified vectors.
Credit: secure@symantec.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veritas Backup Exec | =2010 | |
Veritas Backup Exec | =2010-r3 | |
Veritas Backup Exec | =2012 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4575 has a high severity rating due to its potential to cause a denial of service or execute arbitrary code.
To fix CVE-2013-4575, update Symantec Backup Exec 2010 R3 to SP3 or later, or upgrade Backup Exec 2012 to SP2 or later.
CVE-2013-4575 affects Symantec Backup Exec 2010 R3 prior to SP3 and Backup Exec 2012 before SP2.
CVE-2013-4575 is classified as a heap-based buffer overflow vulnerability.
Yes, CVE-2013-4575 can be exploited remotely by attackers, leading to potential denial of service or arbitrary code execution.