First published: Fri May 29 2015(Updated: )
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell NetVault Backup | =10.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4067 is considered a critical vulnerability due to the potential for remote code execution.
To fix CVE-2015-4067, upgrade to Dell NetVault Backup version 10.0.5 or later.
CVE-2015-4067 is caused by an integer overflow in the libnv6 module leading to a heap-based buffer overflow.
CVE-2015-4067 affects users of Dell NetVault Backup prior to version 10.0.5.
CVE-2015-4067 can be exploited through crafted template string specifiers in serialized objects.