OSVDB ID: 35326

Title: CA BrightStor ARCserve Backup Media Server SUN RPC Service Remote Overflows

Info

Disclosure

Apr 24, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Apr 24, 2007

Description

A buffer overflow exists in ARCserve Backup. The Media Server fails to validate SUN RPC requests resulting in a stack overflow. With a specially crafted request, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Private, Exploit Commercial
Disclosure: Vendor Verified, Vendor Verified, Coordinated Disclosure

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, CA has released a patch to address this vulnerability.

Products

CA

ARCserve Backup

11
11.5
11.1
9.01

BrightStor Enterprise Backup

10.5

Server Protection Suite

r2

Business Protection Suite

r2

References

Credit

  • Tenable Network Security -


Direct URL: http://osvdb.org/35326