BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability
BID:12536
Info
BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 12536 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2005 12:00AM |
| Updated: | Feb 14 2005 12:00AM |
| Credit: | cybertronic <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Computer Associates BrightStor Enterprise Backup for Windows 64 bit 10.5 Computer Associates BrightStor Enterprise Backup for Tru64 10.5 Computer Associates BrightStor Enterprise Backup for Solaris 10.5 Computer Associates BrightStor Enterprise Backup for Solaris 10.0 Computer Associates BrightStor Enterprise Backup for Mainframe Linux 10.0 Computer Associates BrightStor Enterprise Backup for HPUX 10.0 Computer Associates BrightStor Enterprise Backup for HP 10.5 Computer Associates BrightStor Enterprise Backup for AIX 10.5 Computer Associates BrightStor Enterprise Backup for AIX 10.0 Computer Associates BrightStor Enterprise Backup 10.5 Computer Associates BrightStor Enterprise Backup 10.0 Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.1 Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.0 Computer Associates BrightStor ARCServe Backup for Windows 64 bit 9.0.1 Computer Associates BrightStor ARCServe Backup for Windows 11.1 Computer Associates BrightStor ARCServe Backup for Windows 11.0 Computer Associates BrightStor ARCServe Backup for Windows 9.0 .0.1 Computer Associates BrightStor ARCServe Backup for Tru64 11.1 Computer Associates BrightStor ARCServe Backup for Solaris 11.1 Computer Associates BrightStor ARCServe Backup for NetWare 11.1 Computer Associates BrightStor ARCServe Backup for NetWare 9.0 Computer Associates BrightStor ARCServe Backup for Mainframe Linux 11.1 Computer Associates BrightStor ARCServe Backup for Macintosh 11.1 Computer Associates BrightStor ARCServe Backup for Linux Japanese 9.0 Computer Associates BrightStor ARCServe Backup for Linux 11.1 Computer Associates BrightStor ARCServe Backup for Linux 9.0 Computer Associates BrightStor ARCServe Backup for Linux 7.0 Computer Associates BrightStor ARCServe Backup for HP 11.1 Computer Associates BrightStor ARCServe Backup for AIX 11.1 Computer Associates BrightStor ARCserve 2000 Backup Windows Japanese |
| Not Vulnerable: | |
Discussion
BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability
A remote buffer overflow vulnerability reportedly affects BrightStor ARCserve/Enterprise. This issue is due to a failure of the application to securely copy data from the network. It should be noted that this issue is reportedly distinct from that outlined in BID 12522 (BrightStor ARCserve/Enterprise Backup UDP Probe Remote Buffer Overflow Vulnerability).
A remote attacker may execute arbitrary code on a vulnerable computer, potentially facilitating unauthorized superuser access. A denial of service condition may arise as well.
A remote buffer overflow vulnerability reportedly affects BrightStor ARCserve/Enterprise. This issue is due to a failure of the application to securely copy data from the network. It should be noted that this issue is reportedly distinct from that outlined in BID 12522 (BrightStor ARCserve/Enterprise Backup UDP Probe Remote Buffer Overflow Vulnerability).
A remote attacker may execute arbitrary code on a vulnerable computer, potentially facilitating unauthorized superuser access. A denial of service condition may arise as well.
Exploit / POC
BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability
The following exploits have been made available. It should be noted that previously the exploit 'cybertronicBrightStorARCServeBO.c' was associated with BID 12491 (BrightStor ARCserve/Enterprise Backup UDP Probe Remote Buffer Overflow Vulnerability). It has been reported that the issue exploited by 'cybertronicBrightStorARCServeBO.c' is distinct from the issue outlined in that BID.
A Metasploit framework exploit, 'cabrightstor_disco_servicepc.pm', has also been made available.
The following exploits have been made available. It should be noted that previously the exploit 'cybertronicBrightStorARCServeBO.c' was associated with BID 12491 (BrightStor ARCserve/Enterprise Backup UDP Probe Remote Buffer Overflow Vulnerability). It has been reported that the issue exploited by 'cybertronicBrightStorARCServeBO.c' is distinct from the issue outlined in that BID.
A Metasploit framework exploit, 'cabrightstor_disco_servicepc.pm', has also been made available.
Solution / Fix
BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability
Solution:
The vendor has released a patch dealing with this issue in their Microsoft Windows packages. Reportedly patches for other platforms are pending release.
Computer Associates BrightStor Enterprise Backup 10.0
Computer Associates BrightStor Enterprise Backup 10.5
Computer Associates BrightStor ARCServe Backup for Windows 11.0
Computer Associates BrightStor ARCServe Backup for NetWare 11.1
Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.1
Computer Associates BrightStor ARCServe Backup for Windows 11.1
Computer Associates BrightStor ARCServe Backup for Windows 9.0 .0.1
Computer Associates BrightStor ARCServe Backup for NetWare 9.0
Solution:
The vendor has released a patch dealing with this issue in their Microsoft Windows packages. Reportedly patches for other platforms are pending release.
Computer Associates BrightStor Enterprise Backup 10.0
-
Computer Associates QO64544
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6454 4&os=NT&returninput=0
Computer Associates BrightStor Enterprise Backup 10.5
-
Computer Associates QO64540
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6454 0&os=NT&returninput=0
Computer Associates BrightStor ARCServe Backup for Windows 11.0
-
Computer Associates QO64539
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6453 9&os=NT&returninput=0
Computer Associates BrightStor ARCServe Backup for NetWare 11.1
-
Computer Associates QO64543
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6454 3&os=NETWARE&returninput=0
Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.1
-
Computer Associates QO64538
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6453 8&os=NT&returninput=0
Computer Associates BrightStor ARCServe Backup for Windows 11.1
-
Computer Associates QO64538
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6453 8&os=NT&returninput=0
Computer Associates BrightStor ARCServe Backup for Windows 9.0 .0.1
-
Computer Associates QO64542
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6454 2&os=NT&returninput=0
Computer Associates BrightStor ARCServe Backup for NetWare 9.0
-
Computer Associates QO64541
http://supportconnect.ca.com/sc/solcenter/sol_detail.jsp?aparno=QO6454 1&os=NETWARE&returninput=0
References
BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability
References:
References:
- BrightStor ARCserve Backup for Windows Product Page (Computer Associates)
- BrightStor ARCserve Backup Product Page (Computer Associates)
- Metasploit CA BrightStor Discovery Service SERVICEPC Overflow (Metasploit Framework)
- NT -DISCOVERY SERVICE - SECURITY UPDATE (Computer Associates)
- RE: BrightStor ARCserve Backup buffer overflow PoC (fixes available) ("Williams, James K"
)