Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Buffer Overflow Vulnerability
BID:22340
Info
Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 22340 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-0449 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | Mark Litchfield of NGS Software Insight Security Research is credited with the discovery of this issue. |
| Vulnerable: |
Computer Associates ARCserve Backup for Laptops and Desktops 11.1 SP1 Computer Associates ARCserve Backup for Laptops and Desktops 11.1 Computer Associates ARCserve Backup for Laptops and Desktops 11.0 |
| Not Vulnerable: |
Computer Associates ARCserve Backup for Laptops and Desktops 11.1 SP2 |
Discussion
Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Buffer Overflow Vulnerability
Computer Associates BrightStor ARCserve Backup is prone to a remote heap-based buffer-overflow vulnerability because it fails to adequately bounds-checks user-supplied data prior to copying it to an insufficiently sized buffer.
A successful exploit will allow an attacker to execute arbitrary code with SYSTEM-level privileges.
Note that only applications on the Windows operating system are affected.
Computer Associates BrightStor ARCserve Backup is prone to a remote heap-based buffer-overflow vulnerability because it fails to adequately bounds-checks user-supplied data prior to copying it to an insufficiently sized buffer.
A successful exploit will allow an attacker to execute arbitrary code with SYSTEM-level privileges.
Note that only applications on the Windows operating system are affected.
Exploit / POC
Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Buffer Overflow Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
References
Computer Associates BrightStor ARCServe BackUp LGServer Remote Heap Buffer Overflow Vulnerability
References:
References:
- BrightStor ARCserve Backup for Windows Product Page (Computer Associates)
- Remote Unauthenticated Code Execution CA BrightStor ARCserve Backup (NGS Software Insight Security Research)
- Important Security Notice for BrightStor ARCserve Backup for Laptops & Desktops (Computer Associates)