>> CA ARCserve Backup LGServer Service Code Execution Vulnerability
Title : CA ARCserve Backup LGServer Service Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-2286 CVE ID : CVE-2008-3175 CWE ID : CWE-189
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-04
Technical Description
A vulnerability has been identified in CA ARCserve Backup for Laptops and Desktops, CA Desktop Management Suite and CA Protection Suites, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by an integer underflow error in the LGServer service when processing malformed requests sent to port 1900/TCP, which could be exploited by remote attackers to crash an affected service or execute arbitrary code.