APP: Veritas Command Chain
This signature detects attempts to exploit a known vulnerability against Symantec VERITAS NetBackup products. Attackers can chain commands in the request to execute arbitrary commands with elevated privileges or to execute arbitrary code on a vulnerable computer to gain unauthorized access in the context of the application.
Extended Description
NetBackup is prone to multiple vulnerabilities, including two buffer-overflow issues and a privilege-escalation issue. A remote attacker may exploit these issues to execute arbitrary commands with elevated privileges or to execute arbitrary code on a vulnerable computer to gain unauthorized access in the context of the vulnerable application. These vulnerabilities affect all builds and platforms of NetBackup Enterprise Server and client/NetBackup Server and client versions 5.0, 5.1, and 6.0.
Affected Products
Veritas_software netbackup_enterprise_server
References
BugTraq: 21565
CVE: CVE-2006-4092
URL: http://www.symantec.com/avcenter/security/Content/2006.12.13a.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Veritas_software
3.6