Home > Storage Technology News > Symantec fixes 'critical' Veritas flaw
Storage Technology News:
EMAIL THIS

Symantec fixes 'critical' Veritas flaw

By Bill Brenner, News Writer
13 Oct 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Symantec Corp. is urging users of its Veritas NetBackup servers and clients to install updates that plug a security hole that attackers could use to launch malicious code.

The Cupertino, Calif.-based antivirus giant and parent company of Veritas said in an advisory that the problem affects:

  • NetBackup Data and Business Center version 4.5

  • NetBackup Enterprise/Server/Client version 5.0

  • NetBackup Enterprise/Server/Client version 5.1

  • NetBackup Enterprise/Server/Client version 6.0
  • The French Security Incident Response Team (FrSIRT) called the vulnerability "critical" in an advisory issued Wednesday.

    "This flaw is due to a format string error in the Java authentication service 'bpjava-msvc' that does not properly handle a specially crafted 'COMMAND_LOGON_TO_MSERVER' command… which could be exploited by remote attackers to execute arbitrary commands with root/SYSTEM privileges," Symantec said.

    Also in the advisory, Symantec said engineers have verified the issue and made security updates available. The vendor recommended that "all customers immediately apply the latest updates for their supported product versions to protect against these types of threats." The advisory outlines which updates to apply to specific products. Symantec also recommended users block external network access on Transmission Control Protocol (TCP) Port 13722.

    Symantec credited research from TippingPoint, a division of Marlborough, Mass.-based networking vendor 3Com Corp., with reporting the vulnerability. In its advisory, TippingPoint noted that, "authentication is not required to exploit this vulnerability."


    This article originally appeared on SearchSecurity.com.



    Tags: Secure data storageDisaster recovery and planningVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Secure data storage
    Throwing caution to the clouds
    Storage encryption essentials
    Vendors take steps to lock down cloud storage services
    Encryption Special Report: Key management stumbling block to securing data
    What you need to know about storage encryption products
    Isilon targets enterprise NAS with Backup Accelerator, N+2:1 parity
    Storage Decisions Chicago 2009 Session Downloads
    Storage Decisions Session Downloads: Disaster Recovery Track (Chicago 2009)
    Storage Decisions Session Downloads: Data Retention & Retrieval Track (Chicago 2009)
    Data on the brink

    Disaster recovery and planning
    Backup in a snap: A guide to snapshot technologies
    Storage Decisions Chicago 2009 Session Downloads
    Storage Decisions Session Downloads: Disaster Recovery Track (Chicago 2009)
    Storage Decisions Session Downloads: Data Retention & Retrieval Track (Chicago 2009)
    More testing, more confidence for DR plans
    The under-over on DR
    Best storage Products of the Year 2008
    Disaster recovery site options
    DR for virtualized servers
    Storage Decisions San Francisco 2008 Session Downloads

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    hard drive shredder  (SearchStorage.com)
    Storage as a Service (SaaS)  (SearchStorage.com)
    storage encryption  (SearchStorage.com)
    storage security  (SearchStorage.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Backup Solution Directory
    TechTarget Storage Media
    Storage Magazine View this month\\'s issue and subscribe today.
    Storage Decisions Apply online for free conference admission.
    SearchStorage.com
    HomeNewsMagazineTopicsLearningMultimediaWhite PapersBlogsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts