APP: Symantec Veritas NetBackup bpcd.exe Arbitrary Command Execution
This signature detects attempts to exploit a known vulnerability against Symantec Veritas NetBackup. A successful attack can lead to arbitrary command execution.
Extended Description
NetBackup is prone to multiple vulnerabilities, including two buffer-overflow issues and a privilege-escalation issue. A remote attacker may exploit these issues to execute arbitrary commands with elevated privileges or to execute arbitrary code on a vulnerable computer to gain unauthorized access in the context of the vulnerable application. These vulnerabilities affect all builds and platforms of NetBackup Enterprise Server and client/NetBackup Server and client versions 5.0, 5.1, and 6.0.
Affected Products
Veritas_software netbackup_enterprise_server
References
BugTraq: 21565
CVE: CVE-2006-4902
URL: http://www.symantec.com/avcenter/security/content/2006.12.13a.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Veritas_software
10.0