CA Multiple Products Discovery Service Remote Buffer Overflow Vulnerability
BID:20364
Info
CA Multiple Products Discovery Service Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 20364 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5142 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2006 12:00AM |
| Updated: | Nov 22 2006 10:15PM |
| Credit: | livesploit.com is credited with discovering this vulnerability. |
| Vulnerable: |
Computer Associates Server Protection Suite r2 Computer Associates Business Protection Suite for Microsoft SBS Std Ed r2 Computer Associates Business Protection Suite for Microsoft SBS Pre ed r2 Computer Associates Business Protection Suite r2 Computer Associates BrightStor Enterprise Backup 10.5 Computer Associates BrightStor ARCServe Backup for Windows 11.0 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates BrightStor ARCServe Backup 11.1 Computer Associates BrightStor ARCServe Backup 9.01 |
| Not Vulnerable: | |
Discussion
CA Multiple Products Discovery Service Remote Buffer Overflow Vulnerability
Multiple Computer Associates products are prone to a remote stack-based buffer-overflow vulnerability.
This issue arises because these applications fail to perform boundary checks before copying user-supplied data into insufficiently sized buffers.
A successful attack may result in arbitrary code execution with the privileges of the affected application.
This issue affects client and server versions of the affected products.
Multiple Computer Associates products are prone to a remote stack-based buffer-overflow vulnerability.
This issue arises because these applications fail to perform boundary checks before copying user-supplied data into insufficiently sized buffers.
A successful attack may result in arbitrary code execution with the privileges of the affected application.
This issue affects client and server versions of the affected products.
Exploit / POC
CA Multiple Products Discovery Service Remote Buffer Overflow Vulnerability
An exploit for this vulnerability has been used to attack the DeepSight honeypot network. This exploit is not currently known to be publicly available.
An exploit for this vulnerability has been used to attack the DeepSight honeypot network. This exploit is not currently known to be publicly available.
Solution / Fix
CA Multiple Products Discovery Service Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for more information.
References
CA Multiple Products Discovery Service Remote Buffer Overflow Vulnerability
References:
References:
- Computer Associates Homepage (Computer Associates)
- [CAID 34693, 34694]: CA BrightStor ARCserve Backup Multiple Buffer Overflow Vuln (Williams, James K)
- TSRT-06-12: CA BrightStor Discovery Service Mailslot Buffer Overflow Vulnerabili (TippingPoint)
- ZDI-06-030: CA Multiple Product Discovery Service Remote Buffer Overflow Vulnera (ZDI)
- BrightStor ARCserve Backup (Buffer Overrun) (Computer Associates)
- LS-20060220 - Computer Associates BrightStor ARCserve Backup Remote Buffer Overf (LSSEC)