|
|
>> CA BrightStor ARCserve Backup Multiple Remote Command Execution Vulnerabilities
|
Multiple vulnerabilities have been identified in CA BrightStor ARCserve Backup, which could be exploited by remote attackers to take complete control of an affected system. These issues are due to buffer overflow errors in the Tape Engine, Message Engine, and Mediasrv services when processing specially crafted RPC requests sent to ports 6502/TCP, 6503/TCP, and 6504/TCP, which could be exploited by remote unauthenticated attackers to execute arbitrary commands with elevated privileges.
Affected Products
CA BrightStor ARCserve Backup r11.5
CA BrightStor ARCserve Backup r11.1
CA BrightStor ARCserve Backup for Windows r11
CA BrightStor Enterprise Backup r10.5
CA BrightStor ARCserve Backup 9.01
CA Server Protection Suite r2
CA Business Protection Suite r2
CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2
CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2
Solution
Apply patch for BrightStor ARCserve Backup r11.5 :
https://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO84983
Apply patch for BrightStor ARCserve Backup r11.1 :
https://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO84984
Apply patch for BrightStor ARCserve Backup for Windows r11 :
https://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QI82917
Apply patch for BrightStor Enterprise Backup r10.5 :
https://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO84986
Apply patch for BrightStor ARCserve Backup v9.01 :
https://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO84985
References
http://www.vupen.com/english/advisories/2007/0154 http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp http://www.zerodayinitiative.com/advisories/ZDI-07-002.html http://www.zerodayinitiative.com/advisories/ZDI-07-003.html http://www.zerodayinitiative.com/advisories/ZDI-07-004.html http://www.iss.net/threats/252.html http://www.iss.net/threats/253.html http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=467
Credits
Vulnerabilities reported by LSsecurity, Tenable Network Security, Paul Mehta (IBM Internet Security Systems X-Force), ZDI, and iDefense Labs.
ChangeLog
2007-01-12 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|