Veritas Backup Exec 拒绝服务攻击漏洞

漏洞信息详情

Veritas Backup Exec 拒绝服务攻击漏洞

漏洞简介

Windows Servers操作系统下的VERITAS Backup Exec 9.0至10.0版本,以及Netware下的9.0.4019至9.1.307版本中,远程攻击者可借助:(1) NDMLSRVR.DLL中一个特制的数据包,或(2) 一个带有无效(非零)\”错误状态\”值的请求数据包-会引发一个空的解引用,来触发拒绝服务攻击(远程代理崩溃)。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Windows Servers 10.0修订版下的Veritas Software Backup Exec5484

Veritas Software Q175168.BEWS10.0.5520.ESD_277181.zip

http://support.veritas.com/docs/277181

Veritas Software Backup Exec for Windows Servers 10.0 rev. 5484 SP1

Veritas Software be5484RHF24_275514.exe

http://support.veritas.com/docs/275514

Veritas Software Backup Exec for Windows Servers 9.0 rev. 4454 SP1

Veritas Software be4454RHF31_275911.exe

http://support.veritas.com/docs/275911

Veritas Software Backup Exec for Windows Servers 9.0 rev. 4367 SP1

Veritas Software be4367RHF21_276156.exe

http://support.veritas.com/docs/276156

Veritas Software Backup Exec for Windows Servers 9.1 rev. 4691 SP2

Veritas Software be4691RHF52_275909.exe

http://support.veritas.com/docs/275909

参考网址

来源: IDEFENSE

名称: 20050623 Veritas Backup Exec Agent Error Status Remote DoS Vulnerability

链接:http://www.idefense.com/application/poi/display?id=271&type=vulnerabilities

来源: IDEFENSE

名称: 20050623 Veritas Backup Exec Remote Agent NDMLSRVR.DLL DoS Vulnerability

链接:http://www.idefense.com/application/poi/display?id=270&type=vulnerabilities&flashstatus=true

来源: IDEFENSE

名称: 20050623 Veritas Backup Exec Remote Agent NDMLSRVR.DLL DoS Vulnerability

链接:http://www.idefense.com/application/poi/display?id=270&type=vulnerabilities&flashstatus=true

来源: seer.support.veritas.com

链接:http://seer.support.veritas.com/docs/277485.htm

来源: seer.support.veritas.com

链接:http://seer.support.veritas.com/docs/276533.htm

来源: SECTRACK

名称: 1014273

链接:http://securitytracker.com/id?1014273

来源: SECUNIA

名称: 15789

链接:http://secunia.com/advisories/15789

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享