Heap-based Buffer Overflow in Symantec Veritas Storage Foundation
CVE-2008-0638

Currently unrated

Key Information:

Vendor
Symantec
Vendor
CVE Published:
21 February 2008

Summary

A heap-based buffer overflow vulnerability exists in the Veritas Enterprise Administrator service (vxsvc.exe) of Symantec's Veritas Storage Foundation 5.0. This flaw allows remote attackers to exploit the service by sending specially crafted packets with a size field that is not properly validated against the buffer size. Successful exploitation can lead to arbitrary code execution on the affected system, posing significant risks to data integrity and system security. Users and administrators are strongly advised to apply the necessary patches to mitigate this vulnerability.

References

EPSS Score

20% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.