Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> CA BrightStor ARCserve Backup Discovery Service Buffer Overflow

Title : CA BrightStor ARCserve Backup Discovery Service Buffer Overflow
VUPEN ID : VUPEN/ADV-2005-0135
CVE ID : CVE-2005-0260
CWE ID : CWE-
Rated as : High Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-02-10


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

A buffer overflow vulnerability was identified in Computer Associates BrightStor ARCserve Backup Discovery Service, which may be exploited to execute arbitrary code. This flaw is due to a buffer overflow error in the Discovery Service when processing data larger than the temporary buffer (port 41524), which may be exploited by remote attackers to run arbitrary code with SYSTEM privileges.

Affected Products

Computer Associates BrightStor ARCserve Backup 9.x
Computer Associates BrightStor ARCserve Backup 11.x
Computer Associates Enterprise Backup 10.x
Computer Associates ARCserve 2000

Solution

BrightStor ARCserve Backup r11.1 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62769
BrightStor ARCserve Backup r11.0 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62768
BrightStor Enterprise Backup v10.5 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62770
BrightStor Enterprise Backup v10.0 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62771
BrightStor ARCserve Backup v9.01 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62767
BrightStor ARCserve 2000 Backup for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62766
BrightStor ARCserve Backup r11.1 for NetWare :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62936
BrightStor ARCserve Backup v9 for NetWare :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62772
BrightStor ARCserve Backup r11.1 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62990
BrightStor ARCserve Backup r11.0 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62989
BrightStor Enterprise Backup v10.5 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62991
BrightStor ARCserve Backup v9.01 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62987

References

http://www.vupen.com/english/advisories/2005/0135
http://www.idefense.com/application/poi/display?id=194&type=vulnerabilities

Credits

Vulnerability reported by iDefense

ChangeLog

2005-02-10 : Initial release
2005-02-11 : Updated CVE

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7


  >> 2009-05-12

     

  Microsoft Patched 14
  Office PowerPoint Flaws

 

  >> 2009-04-28

     

  Adobe Reader / Acrobat
  Vulnerabilities
Disclosed

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy