Dell NetVault Backup Heap Buffer Overflow Remote Code Execution Vulnerability
Dell NetVault Backup Heap Buffer Overflow Remote Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Dell NetVault Backup
Description:
CVE (CAN) ID: CVE-2015-4067
Dell NetVault Backup is a comprehensive Backup and recovery software solution.
Dell NetVault Backup has a security vulnerability in the implementation of the libnv6 module. Attackers can exploit this vulnerability to manipulate the template string of serialized objects, resulting in integer overflow and arbitrary code execution in the SYSTEM context.
<* Source: sztivi
Link: http://www.zerodayinitiative.com/advisories/ZDI-15-240/
*>
Suggestion:
Vendor patch:
Dell
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://documents.software.dell.com/netvault-backup/10.0.5/release-notes/
This article permanently updates the link address: