[Japanese] | |
JVNDB-2008-001312 | |
Symantec Backup Exec for Windows Server ActiveX Control Multiple Vulnerabilities | |
Overview | |
The PVATLCalendar.PVCalendar.1 (pvcalendar.ocx) ActiveX control, a scheduler component of the Media Server in Symantec Backup Exec for Windows Server (BEWS), includes the insecure Save() method that mishandles strings assigned to certain properties listed below, which can be exploited to cause a denial of service (DoS) or overwrite arbitrary files. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 5.1 (Medium) [NVD Score]
| |
Affected Products | |
| |
Symantec Corporation | |
| |
Impact | |
A remote attacker could cause a denial of service (DoS) or overwrite arbitrary files. | |
Solution | |
Please refer to the 'Vendor Information' section for official countermeasure and take appropriate action. | |
Vendor Information | |
Symantec Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2008/02/29 |
Date First Published | 2008/05/21 |
Date Last Updated | 2008/11/21 |