CVE-2007-2139
Summary
| CVE | CVE-2007-2139 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-25 20:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used in BrightStor ARCserve Backup 9.01 through 11.5 SP2, BrightStor Enterprise Backup 10.5, Server Protection Suite 2, and Business Protection Suite 2, allow remote attackers to execute arbitrary code via malformed RPC strings, a different vulnerability than CVE-2006-5171, CVE-2006-5172, and CVE-2007-1785. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Broadcom | Brightstor Arcserve Backup | 11.1 | All | All | All |
| Application | Broadcom | Brightstor Arcserve Backup | 11.5 | sp2 | All | All |
| Application | Broadcom | Brightstor Arcserve Backup | 9.01 | All | All | All |
| Application | Broadcom | Business Protection Suite | 2.0 | All | All | All |
| Application | Broadcom | Server Protection Suite | 2 | All | All | All |
| Application | Ca | Brightstor Arcserve Backup | 11 | All | windows | All |
| Application | Ca | Business Protection Suite | 2.0 | All | microsoft_sbs_premium | All |
| Application | Ca | Business Protection Suite | 2.0 | All | microsoft_sbs_standard | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Computer Associates BrightStor ArcServe Media Server Multiple Remote Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| CA BrightStor ARCserve Backup Media Server Multiple Buffer Overflows - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| osvdb.org/35326 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| ZDI-07-022 | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Vulnerability Note VU#979825 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp | af854a3a-2127-422b-91ae-364da2661108 | supportconnectw.ca.com | |
| CA BrightStor ArcServe Media Server Buffer Overflows Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.