CVE-2005-3658
Last modified
CVE-2005-3658 is a vulnerability of currently unknown severity. Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).. EPSS estimates a 5.17% chance of exploitation in the next 30 days.
Description
Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emc | Legato Networker | 7.1.1 |
| Emc | Legato Networker | 7.1.2 |
| Emc | Legato Networker | 7.1.3 |
| Emc | Legato Networker | 7.2 |
| Emc | Legato Networker | 7.2.1 |
| Emc | Legato Networker | 7.2_build172 |
References
- http://secunia.com/advisories/18495Patch, Vendor Advisory
- http://secunia.com/advisories/18615Patch, Vendor Advisory
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=373Patch, Vendor Advisory
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=374Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0233Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0343Vendor Advisory
- http://secunia.com/advisories/18495Patch, Vendor Advisory
- http://secunia.com/advisories/18615Patch, Vendor Advisory
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=373Patch, Vendor Advisory
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=374Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0233Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0343Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3658?
How severe is CVE-2005-3658?
How do I fix CVE-2005-3658?
Are you affected by CVE-2005-3658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
