Computer Associates ARCserve Backup for Laptops and Desktops Multiple Remote Vulnerabilities
BID:28616
Info
Computer Associates ARCserve Backup for Laptops and Desktops Multiple Remote Vulnerabilities
| Bugtraq ID: | 28616 |
| Class: | Unknown |
| CVE: |
CVE-2008-1329 CVE-2008-1328 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2008 12:00AM |
| Updated: | Sep 03 2008 08:45PM |
| Credit: | Dyon Balding of Secunia Research |
| Vulnerable: |
Computer Associates Desktop Management Suite 11.2 Computer Associates Desktop Management Suite 11.1 Computer Associates ARCserve Backup for Laptops and Desktops 11.5 Computer Associates ARCserve Backup for Laptops and Desktops 11.1 SP2 Computer Associates ARCserve Backup for Laptops and Desktops 11.1 SP1 Computer Associates ARCserve Backup for Laptops and Desktops 11.1 Computer Associates ARCserve Backup for Laptops and Desktops 11.0 |
| Not Vulnerable: | |
Discussion
Computer Associates ARCserve Backup for Laptops and Desktops Multiple Remote Vulnerabilities
Computer Associates ARCserve Backup for Laptops and Desktops is prone to multiple remote issues, including a buffer-overflow vulnerability and a denial-of-service vulnerability.
Successfully exploiting these issues allows remote attackers to execute arbitrary machine code with SYSTEM-level privileges. This will result in a complete compromise of affected computers. Attackers may also trigger application crashes, denying service to legitimate users.
These issues are related to the ones documented in BID 24348 (Computer Associates ARCserve Backup Multiple Remote Buffer Overflow Vulnerabilities). The fixes for CVE-2007-3216 and CVE-2007-5005 did not completely resolve the previous issues.
Computer Associates ARCserve Backup for Laptops and Desktops is prone to multiple remote issues, including a buffer-overflow vulnerability and a denial-of-service vulnerability.
Successfully exploiting these issues allows remote attackers to execute arbitrary machine code with SYSTEM-level privileges. This will result in a complete compromise of affected computers. Attackers may also trigger application crashes, denying service to legitimate users.
These issues are related to the ones documented in BID 24348 (Computer Associates ARCserve Backup Multiple Remote Buffer Overflow Vulnerabilities). The fixes for CVE-2007-3216 and CVE-2007-5005 did not completely resolve the previous issues.
Exploit / POC
Computer Associates ARCserve Backup for Laptops and Desktops Multiple Remote Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Computer Associates ARCserve Backup for Laptops and Desktops Multiple Remote Vulnerabilities
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
Computer Associates ARCserve Backup for Laptops and Desktops Multiple Remote Vulnerabilities
References:
References:
- CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Sui (Computer Associates)
- Security Notice for CA ARCserve Backup for Laptops and Desktops Server and CA De (Computer Associates)
- CA ARCserve Backup for Laptops and Desktops Server and CA Desktop Management Sui ("Williams, James K"
) - CA ARCserve Backup for Laptops and Desktops Homepage (Computer Associates)