An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely trigger a stack-based buffer overflow on the NetBackup Primary server, resulting in a denial of service.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.veritas.com/content/support/en_US/security/VTS22-004#m3 | patch vendor advisory |