vendor:
NetBackup
by:
johnh[at]digitalmunition[dot]com
7.5
CVSS
HIGH
Format String
Unknown
CWE
Product Name: NetBackup
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Linux
Unknown
VERITAS NetBackup Format Strings Linux/x86 Remote Exploit
This is an exploit for a format string vulnerability in VERITAS NetBackup on Linux/x86. The exploit allows for remote code execution with root privileges. The vulnerability was discovered by kf_lists[at]digitalmunition[dot]com and the exploit was developed by johnh[at]digitalmunition[dot]com. The exploit works by sending a specially crafted request to the target server, triggering the format string vulnerability and executing the provided shellcode.
Mitigation:
Upgrade to a patched version of VERITAS NetBackup.