Update: March 31, 2009
Authentication bypass and buffer overflow vulnerabilities were found in JP1/VERITAS Backup Exec for Windows Servers (SYM08-021).
HS09-001
Vulnerabilities were found in the authentication methods for logging onto a JP1/VERITAS Backup Exec Remote Agent that could allow an unprivileged user to gain unauthorized access to the application.
Once authenticated, the user could further leverage a potential buffer overflow in the data management protocol in an attempt to crash or possibly further compromise the targeted system.
Affected products and Symantec products are listed below. Please upgrade to the appropriate version.
The information is organized under the following headings:
Version:
Version(s):
Version(s):
Version(s):
For details on the fixed products, contact your Hitachi support service representative.