Secunia Logo
 
CVE Reference: CVE-2007-1785
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-1785

Description:
The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/33316

ST
  1017830

SREASON
  http://securityreason.com/securityalert/2509

SAID
  Secunia Advisory: SA24682

MISC
  http://www.shirkdog.us/camediasvrremote.py
  http://www.shirkdog.us/shk-004.html

CONFIRM
  http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp

CERT-VN
  151305

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/464343/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/464270/100/0/threaded

BID
  23209


Return to the previous page.