SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

CA BrightStor ARCserve Backup Discovery Service Buffer Overflow Vulnerability


Arrow  SecurityAlert : 2010
Arrow  CVE : CVE-2006-6379
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : Yes
Arrow  Exploit Available : No
Arrow  Credit : Williams, James K (James Williams ca com)
Arrow  Published : 11.12.2006

Arrow  Affected Software : Computer Associates, BrightStor ARCserve Backup, r11.5 SP1
Computer Associates, BrightStor ARCserve Backup, 9.01
Computer Associates, BrightStor ARCServe Backup, 11.5
Computer Associates, BrightStor ARCServe Backup, 11.1
Computer Associates, BrightStor ARCServe Backup, 11.0
Computer Associates, BrightStor Enterprise Backup, 10.5
Computer Associates, Server Protection Suite, r2




Arrow  Advisory Content :  


Title: CAID 34846: CA BrightStor ARCserve Backup Discovery Service

Buffer Overflow Vulnerability

CA Vulnerability ID (CAID): 34846

CA Advisory Date: 2006-12-07

Discovered By: Assurent Secure Technologies (assurent.com)

Impact: Remote attacker can execute arbitrary code.

Summary: CA BrightStor ARCserve Backup contains a buffer overflow

that allows remote attackers to execute arbitrary code with local

SYSTEM privileges on Windows. This issue affects the BrightStor

Backup Discovery Service in multiple BrightStor ARCserve Backup

application agents and the Base product.

Mitigating Factors: None.

Severity: CA has given this vulnerability a High risk rating.

Affected Products:

BrightStor Products:

- BrightStor ARCserve Backup r11.5 SP1 and below (SP2 does not

have this vulnerability ; please apply r11.5 SP2)

- BrightStor ARCserve Backup r11.1

- BrightStor ARCserve Backup for Windows r11

- BrightStor Enterprise Backup 10.5

- BrightStor ARCserve Backup v9.01

CA Protection Suites r2:

- CA Server Protection Suite r2

- CA Business Protection Suite r2

- CA Business Protection Suite for Microsoft Small Business Server

Standard Edition r2

- CA Business Protection Suite for Microsoft Small Business Server

Premium Edition r2

Affected platforms:

Microsoft Windows

Status and Recommendation:

Customers with vulnerable versions of BrightStor ARCserve Backup

products should upgrade to the latest versions which are available

for download from http://supportconnect.ca.com.

Solution Document Reference APARs:

QO84609, QI82917, QO84611, QO84610

Determining if you are affected:

For a list of updated files, and instructions on how to verify

that the security update was fully applied, please review the

Informational Solution referenced in the appropriate Solution

Document.

References (URLs may wrap):

CA SupportConnect:

http://supportconnect.ca.com/

CA SupportConnect Security Notice for this vulnerability:

Important Security Notice for BrightStor ARCserve Backup

http://supportconnectw.ca.com/public/storage/infodocs/babsecurity-notice
.asp

Solution Document Reference APARs:

QO84609, QI82917, QO84611, QO84610

CA Security Advisor Research Blog postings:

http://www3.ca.com/blogs/posting.aspx?id=90744&pid=96149&date=2006/12

CAID: 34846

CAID Advisory links:

http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34846

Discoverer: Assurent Secure Technologies

http://www.assurent.com/

CVE Reference: CVE-2006-6379

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6379

OSVDB Reference: OSVDB IDs: 30775

http://osvdb.org/30775

Changelog for this advisory:

v1.0 - Initial Release

Customers who require additional information should contact CA

Technical Support at http://supportconnect.ca.com.

For technical questions or comments related to this advisory,

please send email to vuln (at) ca (dot) com [email concealed], or contact
me directly.

If you discover a vulnerability in CA products, please report

your findings to vuln (at) ca (dot) com [email concealed], or utilize our
"Submit a

Vulnerability" form.

URL: http://www3.ca.com/securityadvisor/vulninfo/submit.aspx

Regards,

Ken Williams ; 0xE2941985

Director, CA Vulnerability Research

CA, One CA Plaza. Islandia, NY 11749

Contact http://www3.ca.com/contact/

Legal Notice http://www3.ca.com/legal/

Privacy Policy http://www3.ca.com/privacy/

Copyright © 2006 CA. All rights reserved.





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

» PHP 5.3.0 5.2.11
   posix_mkfifo()
   open_basedir bypass

Copyright © SecurityReason.com. All Rights Reserved.