Document ID: 276606
http://support.veritas.com/docs/276606
E-Mail Colleague IconE-Mail this document to a colleague

VERITAS Software Security Advisory VX05-005

Details:
VX05-005
June 22, 2005
Buffer overflow vulnerability in VERITAS Software Backup Exec Web Administration Console (BEWAC)

Revision History
None


Risk Impact
High


Overview
The Backup Exec Web Administration Console (BEWAC) is a Web utility option that can be installed on a Backup Exec media server, which allows remote management of that media server. Exploitation of a buffer overflow vulnerability in the Web Administration Console may allow a user to execute arbitrary code.  


Affected Products
Backup Exec 10.0 for Windows Servers rev. 5484
Backup Exec 9.1 for Windows Servers rev. 4691
Backup Exec 9.0 for Windows Servers rev. 4454
Backup Exec 9.0 for Windows Servers rev. 4367


Non-Affected Products
Backup Exec 10.0 for Windows Servers rev. 5520


Details
NGSSoftware (  http://www.ngssoftware.com/advisory.htm ) reported a buffer overflow vulnerability in VERITAS Software Backup Exec Web Administration Console that can potentially allow a user to execute arbitrary code. The vulnerability exists due to improper handling of specifically configured user-provided credentials. Successful exploitation of this issue could lead to privileged access on the targeted system.


VERITAS Software's Response
VERITAS Engineering has verified and addressed the issue in the affected products using the Web Administration Console. A hotfix has been developed for each of the affected versions to address the issue. Even though VERITAS Technical Services is unaware of any adverse customer impact from this issue, we strongly recommend users of the affected products apply the appropriate upgrade and/or updates immediately to safeguard against threats of this nature.

NOTE:  Customers running VERITAS Backup Exec 9.0 rev. 4367 and VERITAS Backup Exec 9.0 rev. 4454 MUST upgrade to VERITAS Backup Exec 9.1 rev. 4691, and then apply the security rollup to resolve this issue.  This is a free upgrade for all users of VERITAS Backup Exec 9.0 rev. 4367 and VERITAS Backup Exec 9.0 rev. 4454.  

If the upgrade cannot be performed within an acceptable period due to change control or other mitigating issues, be sure to follow the instructions in the mitigation section for instructions on disabling the Backup Exec Web Administration Console.

VERITAS Backup Exec 9.1 rev. 4691 for Windows Servers Installation Media

VERITAS Backup Exec 9.1 rev. 4691 for Windows Servers Service Pack 4

VERITAS Backup Exec 10.0 rev. 5484 for Windows Servers Hotfix 24

or

VERITAS Backup Exec 10.0 rev. 5484 for Windows Servers - upgrade to Backup Exec 10.0 rev. 5520


Mitigation
A. Remove the Backup Exec Web Administration Console

1.  Launch the Backup Exec Setup from Add/Remove Programs
2.  Uninstall Backup Exec
3.  Reinstall Backup Exec without the Web Administration Console (BEWAC)

B. Rename or delete Inc_debug.asp

CVE
A CVE candidate number will be requested from The Common Vulnerabilities and Exposures (CVE) initiative. This advisory will be revised as required once the CVE candidate number has been assigned.  This issue is a candidate for inclusion in the CVE list (  http://cve.mitre.org ) which standardizes names for security problems.


Credit
VERITAS Software appreciates the cooperation of the NGSSoftware research team in identifying this issue and coordinating with VERITAS Software in the resolution process.


Products Applied:
 Backup Exec for Windows Servers 10.0, 10.0 5484, 9.0, 9.0 4367, 9.0 4454, 9.1, 9.1 4691

Last Updated: October 14 2005 02:34 PM GMT
Expires on: 365 days from publish date
Subscribe Via E-Mail IconSubscribe to receive critical updates about this document

Subjects:
 Backup Exec for Windows Servers
   Application: Backup, Documentation, Faq, Restore, Troubleshooting
   Publishing Status: Techalert

Languages:
 English (US), French, German, Spanish, Italian, Japanese, Chinese, Korean

Operating Systems:
Windows 2000

Advanced Server, Advanced Server Windows Powered, Datacenter Server, Professional, SAK, Server, Server Windows Powered

Windows NT

4.0 Server SP6a, 4.0 Workstation SP6a

Windows NT Small Business Server

2000, 4.5

Windows XP

Home 5.1, Pro 5.1

Windows Server 2003

DataCenter, Enterprise Server, Standard Server, Storage Server, Web Server

Windows Small Business Server 2003

Premium Edition, Standard Edition