vendor:
BackupExec
by:
JJ Reyes
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: BackupExec
Affected Version From: 10.0.0.17
Affected Version To: 10.0.0.17
Patch Exists: Yes
Related CWE: N/A
CPE: a:symantec:backup_exec:10.0.0.17
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2008
Symantec BackupExec Calendar Control(PVCalendar.ocx) BoF Exploit
This exploit is a buffer overflow vulnerability in the Symantec BackupExec Calendar Control (PVCalendar.ocx) ActiveX control. It was discovered by JJ Reyes of Secunia Research and tested on Windows XP SP2 (fully patched) English, IE6 and IE7, PVCalendar.ocx version 10.0.0.17. It was written by e.b. and thanks to h.d.m. and the Metasploit crew.
Mitigation:
Disable the ActiveX control in the browser or uninstall the vulnerable version of the software.