CVE-2007-2359Improper Restriction of Operations within the Bounds of a Memory Buffer in Backupexec System Recovery

4 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 69.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 1

Description

Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages4 packages

NVDsymantec/norton_ghost10.0, 10.01+1
NVDsymantec/livestate_recovery6.0, 6.01, 6.02+2

🔴Vulnerability Details

2
GHSA
GHSA-9vjc-rvgp-29xx: Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery2022-05-01
CVEList
CVE-2007-2359: Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery2007-04-30

💥Exploits & PoCs

1
Exploit-DB
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection2007-03-23
CVE-2007-2359 — Symantec vulnerability | cvebase