Details
IDefense, notified Symantec of a DoS identified in one of the RPC interfaces in Symantec Backup Exec for Window Servers. The DoS occurs due to improper validation and subsequent handling of user input. Successful exploitation requires access to the service port which in a normal installation would require the attacker to have authorized but non-privileged access to the network on which the targeted server resides to leverage network communications. A successful attack would normally result in termination of the targeted service however, there is a slight potential that a sufficiently designed and implemented attack could possibly result in arbitrary code execution on and elevated access to the targeted system.
The Common Vulnerabilities and Exposures (CVE) initiative has assigned CVE Candidate CVE-2007-3509 to this issue.
This issue is a candidate for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.
SecurityFocus has assigned Bugtraq ID BID 23897 to this issue for inclusion in the SecurityFocus vulnerability database
Thanks for your feedback. Let us know if you have additional comments below. (requires login)