Symantec plugs vulnerabilities in NetBackup
Symantec says it has fixed vulnerabilities in its NetBackup storage software identified by TippingPoint.
A brace of good ol' buffer overflow problems hit the backup program, meaning "A remote attacker who successfully gains access to the targeted system can append commands to a valid command and potentially leverage this issue to run arbitary commands with elevated privilege on the targeted system."
Symantec says there are no known exploitations so far. Maintenance updates are now available to patch the holes. In a statement, the firm said: "Symantec takes the security of our products and our customers very seriously." You'd hope.
"Symantec engineers have verified and corrected these issues in all currently supported versions of NetBackup," the firm added.
An internal review recently identified other security quibbles in NetBackup, which Symantec was working on fixing when the two new ones were Tipping-Pointed out.
The fixes are available here. ®