[Japanese] | |
JVNDB-2008-001311 | |
Symantec Backup Exec for Windows Server ActiveX Control Multiple Buffer Overflow Vulnerabilities | |
Overview | |
The PVATLCalendar.PVCalendar.1 (pvcalendar.ocx) ActiveX control, a scheduler component of the Media Server in Symantec Backup Exec for Windows Server (BEWS), includes the insecure Save() method that mishandles long strings assigned to various properties listed below, which can be exploited to cause stack-based buffer overflows. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 9.3 (High) [NVD Score]
| |
Affected Products | |
| |
Symantec Corporation | |
| |
Impact | |
A remote attacker could execute arbitrary code. | |
Solution | |
Please refer to the 'Vendor Information' section for official countermeasure and take appropriate action. | |
Vendor Information | |
Symantec Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2008/02/29 |
Date First Published | 2008/05/21 |
Date Last Updated | 2008/11/21 |