CVE-2005-3116
Veritas NetBackup 4/5 - Volume Manager Daemon Remote Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute arbitrary code via a crafted packet.
Exploitation of a buffer overflow vulnerability in Veritas Netbackup could lead to a remote Denial Of Service or remote code execution. The Veritas Netbackup Volume Manager keeps track of the location of volumes (tapes) needed for backup or restore. By sending a specially crafted packet to the Volume Manager stack overflow occurs. This is caused by improper bounds checking. Confirmed vulnerable: Veritas Netbackup 5.0 with MP1 (vmd.exe 5.0.0.370), Veritas Netbackup 5.0 with MP2 (vmd.exe 5.0.0.372), Veritas Netbackup 5.0 with MP3 (vmd.exe 5.0.0.377), Veritas Netbackup 5.0 with MP4 (vmd.exe 5.0.0.382), Veritas Netbackup 5.0 with MP5 (vmd.exe 5.0.0.387), Veritas Netbackup 5.1 without MP (vmd.exe 5.1.0.135), Veritas Netbackup 5.1 with MP1 (vmd.exe 5.1.0.140), Veritas Netbackup 5.1 with MP2 (vmd.exe 5.1.0.146), Veritas Netbackup 5.1 with MP3A (vmd.exe 5.1.0.150).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2005-09-30 CVE Reserved
- 2005-11-12 CVE Published
- 2006-01-16 First Exploit
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://www.vupen.com/english/advisories/2005/2349 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22985 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/43245 | 2006-01-21 | |
https://www.exploit-db.com/exploits/1421 | 2006-01-16 | |
http://www.securityfocus.com/archive/1/422066/100/0/threaded | 2024-08-07 | |
http://www.securityfocus.com/archive/1/422157/100/0/threaded | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/17503 | 2017-07-11 | |
http://securityresponse.symantec.com/avcenter/security/Content/2005.11.08b.html | 2017-07-11 | |
http://securitytracker.com/id?1015170 | 2017-07-11 | |
http://seer.support.veritas.com/docs/279553.htm | 2017-07-11 | |
http://www.idefense.com/application/poi/display?id=336&type=vulnerabilities | 2017-07-11 | |
http://www.kb.cert.org/vuls/id/574662 | 2017-07-11 | |
http://www.osvdb.org/20674 | 2017-07-11 | |
http://www.securityfocus.com/bid/15353 | 2017-07-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.0_with_mp1 Search vendor "Symantec Veritas" for product "Netbackup" and version "5.0_with_mp1" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.0_with_mp2 Search vendor "Symantec Veritas" for product "Netbackup" and version "5.0_with_mp2" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.0_with_mp3 Search vendor "Symantec Veritas" for product "Netbackup" and version "5.0_with_mp3" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.0_with_mp4 Search vendor "Symantec Veritas" for product "Netbackup" and version "5.0_with_mp4" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.0_with_mp5 Search vendor "Symantec Veritas" for product "Netbackup" and version "5.0_with_mp5" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.1_with_mp1 Search vendor "Symantec Veritas" for product "Netbackup" and version "5.1_with_mp1" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.1_with_mp2 Search vendor "Symantec Veritas" for product "Netbackup" and version "5.1_with_mp2" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.1_with_mp3a Search vendor "Symantec Veritas" for product "Netbackup" and version "5.1_with_mp3a" | - |
Affected
| ||||||
Symantec Veritas Search vendor "Symantec Veritas" | Netbackup Search vendor "Symantec Veritas" for product "Netbackup" | 5.1_without_mp Search vendor "Symantec Veritas" for product "Netbackup" and version "5.1_without_mp" | - |
Affected
|