Computer Associates BrightStor ArcServe Media Server Multiple Remote Buffer Overflow Vulnerabilities
BID:23635
Info
Computer Associates BrightStor ArcServe Media Server Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 23635 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-2139 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2007 12:00AM |
| Updated: | Jan 28 2009 09:59PM |
| Credit: | Tenable Network Security is credited with discovering these issues. |
| Vulnerable: |
Computer Associates Server Protection Suite r2 Computer Associates Business Protection Suite r2 Computer Associates BrightStor ARCServe Backup 11.1 Computer Associates BrightStor ARCServe Backup 9.01 Computer Associates BrightStor ARCServe Backup 11.5.SP2 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates BrightStor ARCServe Backup 11 Computer Associates BrightStor ARCServe Backup 10.5 |
| Not Vulnerable: | |
Discussion
Computer Associates BrightStor ArcServe Media Server Multiple Remote Buffer Overflow Vulnerabilities
Computer Associates BrightStor ARCServe Media Server is prone to multiple remote buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
A remote attacker may exploit these issues to execute arbitrary code with SYSTEM-level privileges. Successful exploits can result in a complete compromise of affected computers. Failed exploit attempts will likely cause denial-of-service conditions.
Computer Associates BrightStor ARCServe Media Server is prone to multiple remote buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
A remote attacker may exploit these issues to execute arbitrary code with SYSTEM-level privileges. Successful exploits can result in a complete compromise of affected computers. Failed exploit attempts will likely cause denial-of-service conditions.
Exploit / POC
Computer Associates BrightStor ArcServe Media Server Multiple Remote Buffer Overflow Vulnerabilities
Exploits for one or more of these issues may be available to members of the Immunity Partner's program. The exploits are not known to be publicly available; we do not have enough information to conclusively state that they exploit a vulnerability described in this BID.
The exploits may be obtained from the following URI:
https://www.immunityinc.com/downloads/immpartners/ca_mediasvr.tar.gz
https://www.immunityinc.com/downloads/immpartners/ca_mediasvr.tar
UPDATE (January 28, 2009): Symantec detected active exploits for one of these issues in the wild.
The following exploit code is available as a module from the Metasploit Framework:
Exploits for one or more of these issues may be available to members of the Immunity Partner's program. The exploits are not known to be publicly available; we do not have enough information to conclusively state that they exploit a vulnerability described in this BID.
The exploits may be obtained from the following URI:
https://www.immunityinc.com/downloads/immpartners/ca_mediasvr.tar.gz
https://www.immunityinc.com/downloads/immpartners/ca_mediasvr.tar
UPDATE (January 28, 2009): Symantec detected active exploits for one of these issues in the wild.
The following exploit code is available as a module from the Metasploit Framework:
Solution / Fix
Computer Associates BrightStor ArcServe Media Server Multiple Remote Buffer Overflow Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
Computer Associates BrightStor ARCServe Backup 10.5
Computer Associates BrightStor ARCServe Backup 9.01
Computer Associates BrightStor ARCServe Backup 11.5.SP2
Computer Associates BrightStor ARCServe Backup 11
Computer Associates BrightStor ARCServe Backup 11.1
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
Computer Associates BrightStor ARCServe Backup 10.5
-
Computer Associates QO87575
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87 575
Computer Associates BrightStor ARCServe Backup 9.01
-
Computer Associates QO87574
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87 574
Computer Associates BrightStor ARCServe Backup 11.5.SP2
-
Computer Associates QO87569
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87 569
Computer Associates BrightStor ARCServe Backup 11
-
Computer Associates QI82917
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QI82 917
Computer Associates BrightStor ARCServe Backup 11.1
-
Computer Associates QO87573
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO87 573
References
Computer Associates BrightStor ArcServe Media Server Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- BrightStor ARCserve Backup Media Server Security Notice (Computer Associates)
- BrightStor ARCserve Backup Product Page (Computer Associates)
- ZDI-07-022: CA BrightStor ArcServe Media Server Multiple Buffer Overflow Vulnera (ZDI)
- [CAID 35198, 35276]: CA BrightStor ARCserve Backup Media Server Vulnerabilities (Computer Associates)
- ZDI-07-022: CA BrightStor ArcServe Media Server Multiple Buffer Overflow Vulnera ([email protected])
- Vulnerability Note VU#979825 CA BrightStor ARCserve Backup Media Server RPC serv (US-CERT)