|
|
>> CA BrightStor ARCserve Backup Discovery Service Buffer Overflow
|
Title : CA BrightStor ARCserve Backup Discovery Service Buffer Overflow VUPEN ID : VUPEN/ADV-2005-0135 CVE ID : CVE-2005-0260 CWE ID : CWE-
Rated as : High Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-02-10
|
A buffer overflow vulnerability was identified in Computer Associates BrightStor ARCserve Backup Discovery Service, which may be exploited to execute arbitrary code. This flaw is due to a buffer overflow error in the Discovery Service when processing data larger than the temporary buffer (port 41524), which may be exploited by remote attackers to run arbitrary code with SYSTEM privileges.
Affected Products
Computer Associates BrightStor ARCserve Backup 9.x
Computer Associates BrightStor ARCserve Backup 11.x
Computer Associates Enterprise Backup 10.x
Computer Associates ARCserve 2000
Solution
BrightStor ARCserve Backup r11.1 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62769
BrightStor ARCserve Backup r11.0 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62768
BrightStor Enterprise Backup v10.5 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62770
BrightStor Enterprise Backup v10.0 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62771
BrightStor ARCserve Backup v9.01 for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62767
BrightStor ARCserve 2000 Backup for Windows :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62766
BrightStor ARCserve Backup r11.1 for NetWare :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62936
BrightStor ARCserve Backup v9 for NetWare :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62772
BrightStor ARCserve Backup r11.1 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62990
BrightStor ARCserve Backup r11.0 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62989
BrightStor Enterprise Backup v10.5 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62991
BrightStor ARCserve Backup v9.01 for Windows - 64 Bit Edition :
supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO62987
References
http://www.vupen.com/english/advisories/2005/0135 http://www.idefense.com/application/poi/display?id=194&type=vulnerabilities
Credits
Vulnerability reported by iDefense
ChangeLog
2005-02-10 : Initial release
2005-02-11 : Updated CVE
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|