Secunia Logo
Netsikker nu! 2008
 
CA BrightStor ARCserve Backup Media Server Multiple Buffer Overflows
Secunia Advisory: SA24972
Release Date: 2007-04-25
Last Update: 2007-04-26
Popularity: 7,905 views

Critical:
Moderately critical
Impact: System access
Where: From local network
Solution Status: Vendor Patch

Software:BrightStor ARCserve Backup 11.x
BrightStor ARCserve Backup 11.x (for Microsoft SQL Server)
BrightStor ARCserve Backup 11.x (for Windows)
BrightStor ARCserve Backup 9.x
BrightStor Enterprise Backup 10.x

Binary Analysis: BA95 :: Available for 1 Credit

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-2139


Description:
Some vulnerabilities have been reported in BrightStor ARCserve Backup, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerabilities are caused due to boundary errors within the SUN RPC service when processing RPC strings. These can be exploited to cause stack-based buffer overflows via specially crafted RPC strings sent to the service.

Successful exploitation allows execution of arbitrary code.

The vulnerabilities affect the following products and versions:
* BrightStor ARCserve Backup r11.5
* BrightStor ARCserve Backup r11.1
* BrightStor ARCserve Backup r11 for Windows
* BrightStor Enterprise Backup r10.5
* BrightStor ARCserve Backup v9.01
* CA Server Protection Suite r2
* CA Business Protection Suite r2
* CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2
* CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2

Solution:
Apply patches.

BrightStor ARCserve Backup r11.5 SP3 - QO87569:
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87569

BrightStor ARCserve Backup r11.5 SP2 - QO87570:
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87570

BrightStor ARCserve Backup r11.1 - QO87573:
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87573

BrightStor ARCserve Backup r11.0 - QI82917:
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QI82917

BrightStor Enterprise Backup r10.5 - QO87575:
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87575

BrightStor ARCserve Backup v9.01 - QO87574:
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87574

Provided and/or discovered by:
Discovered by Tenable Network Security and reported via ZDI.

Changelog:
2007-04-26: Added link to US-CERT.

Original Advisory:
CA:
http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-07-022.html

Other References:
US-CERT VU#979825:
http://www.kb.cert.org/vuls/id/979825


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB Avatar Script Insertion Vulnerability // 41 views
2. phpBB Avatar Functions Information Disclosure and Deletion // 37 views
3. CUPS Multiple Vulnerabilities // 37 views
4. Sun Java System Web Proxy Server FTP Subsystem Buffer Overflow // 37 views
5. CA ARCserve Backup Multiple Vulnerabilities // 36 views
6. ScriptsEz Easy Image Downloader "id" File Disclosure Vulnerability // 34 views
7. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities // 34 views
8. phpBB reveals user IPs // 28 views
9. phpBB Cross Site Scripting and Unspecified Vulnerabilities // 27 views
10. FUJITSU Interstage Products Apache Tomcat Security Bypass // 26 views