The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://secunia.com/advisories/50957 | third party advisory |
http://osvdb.org/86158 | vdb entry |
http://www.securityfocus.com/bid/55883 | vdb entry |
http://www.securitytracker.com/id?1027647 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2012-10/0068.html | mailing list |