Vulnerability Description
Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2008-5407.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Backup Exec For Windows Server | 11d |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/32810Vendor Advisory
- http://securityresponse.symantec.com/avcenter/security/Content/2008.11.19.htmlPatchVendor Advisory
- http://seer.entsupport.symantec.com/docs/314528.htmPatchVendor Advisory
- http://www.securityfocus.com/bid/32346Patch
- http://www.securitytracker.com/id?1021246
- http://www.vupen.com/english/advisories/2008/3209
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46731
- http://secunia.com/advisories/32810Vendor Advisory
- http://securityresponse.symantec.com/avcenter/security/Content/2008.11.19.htmlPatchVendor Advisory
- http://seer.entsupport.symantec.com/docs/314528.htmPatchVendor Advisory
- http://www.securityfocus.com/bid/32346Patch
- http://www.securitytracker.com/id?1021246
- http://www.vupen.com/english/advisories/2008/3209
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46731
FAQ
What is CVE-2008-5408?
CVE-2008-5408 is a vulnerability with a CVSS score of 9.0 (HIGH). Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users ...
How severe is CVE-2008-5408?
CVE-2008-5408 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5408?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Backup Exec For Windows Server.