4.6

CVE-2006-1298

Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev. 5629, Backup Exec 10.0 for Windows Servers rev. 5520, Backup Exec 10.0 for Windows Servers rev. 5484, and Backup Exec 9.1 for Windows Servers rev. 4691, when the job log mode is Full Detailed (aka Full Details), allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted filename on a machine that is backed up by Backup Exec.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Symantec VeritasBackup Exec Version9.1
Symantec VeritasBackup Exec Version10.0 Editionwindows_servers
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.95% 0.776
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 3.9 6.4
AV:N/AC:H/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19242
http://securitytracker.com/id?1015785
http://support.veritas.com/docs/282254
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/428223/100/0/threaded
http://www.securityfocus.com/bid/17096
Patch
http://www.symantec.com/avcenter/security/Content/2006.03.17b.html
http://www.vupen.com/english/advisories/2006/0996
https://exchange.xforce.ibmcloud.com/vulnerabilities/25310