Tech

Guides
 

Symantec plugs trio of NetBackup holes

By Joris Evers, CNET News.com
Wednesday, January 03, 2007 03:16 PM

Serious security vulnerabilities in Veritas NetBackup software could let cyberattackers get into corporate networks.

Symantec has released updates for its Veritas NetBackup software to repair a trio of serious security vulnerabilities.

The flaws affect Veritas NetBackup Master, Media Servers and clients, the Cupertino, Calif.-based company said in a security alert. An attacker with access to a vulnerable NetBackup host could gain complete control over the targeted system, it said.

Two of the flaws are buffer overflow problems in the NetBackup bpcd communications daemon running on the NetBackup servers and client systems, Symantec said. It also affects the daemon running on Storage Migrator for Unix, if that option is installed. These issues were reported through TippingPoint's bug bounty program, Symantec said.

The third issue is a programming logic error in how the same bpcd daemon handles incoming system commands. This problem was discovered by IBM's Internet Security Systems.

Symantec found additional potential security problems during a review of the NetBackup code, it said. Those unspecified issues have also been addressed in the updates.

In recommended installations, Veritas NetBackup systems should be configured to restrict access to trusted hosts only and not be exposed to the Internet. This would limit any possible attacks to the insiders, Symantec said.

The software affected are versions 5.0, 5.1 and 6.0 of NetBackup server and client software, plus the Storage Migrator for Unix option. There are no current attacks that take advantage of any of the flaws, Symantec said. The updates are available on the company's Web site.



WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Getting credit for having a BCP

Blog thumbnail

In July U.S. credit rating agency Standard & Poor's (S&P) started evaluating the enterprise risk management (ERM) capabilities of non-financial companies that it covers. This is S&P's announcement, and here..... by Nathaniel Forbes

Read more »

Whitepapers / Case Studies

Downloads

Disaster Recovery News

 
Test drive Red Hat Enterprise Linux Advanced Platform
Why pay thousands of dollars more per server for critical applications and technologies when you can have it in a single, fully integrated solution?
Test Drive Now!
» Unlimited virtualized guests.
» Storage virtualization.
» High availability clustering and failover.


Growing your business means sharpening your IT infrastructure
Strengthen your IT foundation with reliable and affordable technology for your expanding business.
» Powerful server blade for SMBs
» Simplify storage with virtualization
» Make a move to energy-efficient blade technology

Tech Jobs Now!

Tags

  1. access
  2. by
  3. dev
  4. do
  5. easily
  6. easy
  7. excel
  8. keep
  9. know
  10. letters
  11. make
  12. mount
  13. openssh
  14. pc
  15. print
  16. printing
  17. program
  18. project
  19. save
  20. scripting
  21. security
  22. server
  23. sql
  24. time
  25. users
  26. using
  27. web
  28. what
  29. windows
  30. word