CVE Vulnerabilities

CVE-2006-4902

Published: Dec 14, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malicious commands to valid commands.

Affected Software

Name Vendor Start Version End Version
Veritas_netbackup_client Symantec 5.0 (including) 5.0 (including)
Veritas_netbackup_client Symantec 5.1 (including) 5.1 (including)
Veritas_netbackup_client Symantec 6.0 (including) 6.0 (including)
Veritas_netbackup_enterprise_server Symantec 5.0 (including) 5.0 (including)
Veritas_netbackup_enterprise_server Symantec 5.1 (including) 5.1 (including)
Veritas_netbackup_enterprise_server Symantec 6.0 (including) 6.0 (including)
Veritas_netbackup_server Symantec 5.0 (including) 5.0 (including)
Veritas_netbackup_server Symantec 5.1 (including) 5.1 (including)
Veritas_netbackup_server Symantec 6.0 (including) 6.0 (including)

References