Multiple integer overflows in the Job Engine (bengine.exe) service in...
Vulnerability Description
Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allow remote attackers to cause a denial of service (CPU and memory consumption) via a crafted packet to port 5633/tcp, which triggers an infinite loop.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4347
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38677
- http://secunia.com/advisories/26975
- http://securityresponse.symantec.com/avcenter/security/Content/2007.11.27.html
- http://www.securityfocus.com/archive/1/484318/100/0/threaded
- http://secunia.com/secunia_research/2007-74/advisory/
- http://www.securityfocus.com/bid/26029
- http://www.securityfocus.com/archive/1/484333/100/0/threaded
- http://www.vupen.com/english/advisories/2007/4019
- http://www.securitytracker.com/id?1019001
More from symantec
View All →Affected Vendor
symantec
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.