Computer Associates ARCserve Backup Discovery Service Remote Denial Of Service Vulnerability
BID:28927
Info
Computer Associates ARCserve Backup Discovery Service Remote Denial Of Service Vulnerability
| Bugtraq ID: | 28927 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1979 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2008 12:00AM |
| Updated: | Jun 18 2008 09:41PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Computer Associates Server Protection Suite r2 SP1 Computer Associates Server Protection Suite r2 Computer Associates Protection Suites r2 0 Computer Associates BrightStor ARCServe Backup 11.1 Computer Associates BrightStor ARCServe Backup 11.5.SP3 Computer Associates BrightStor ARCServe Backup 11.5.SP2 Computer Associates BrightStor ARCServe Backup 11.5.SP1 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates ARCserve Backup 12.0.5454 .0 |
| Not Vulnerable: | |
Discussion
Computer Associates ARCserve Backup Discovery Service Remote Denial Of Service Vulnerability
Computer Associates ARCserve Backup is affected by a denial-of-service vulnerability because the application mishandles malformed user-supplied input.
A remote attacker may exploit this issue to cause denial-of-service conditions.
CA ARCserve Backup 12.0.5454.0 is affected by this issue; other versions may also be vulnerable.
Computer Associates ARCserve Backup is affected by a denial-of-service vulnerability because the application mishandles malformed user-supplied input.
A remote attacker may exploit this issue to cause denial-of-service conditions.
CA ARCserve Backup 12.0.5454.0 is affected by this issue; other versions may also be vulnerable.
Exploit / POC
Computer Associates ARCserve Backup Discovery Service Remote Denial Of Service Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Computer Associates ARCserve Backup Discovery Service Remote Denial Of Service Vulnerability
Solution:
The vendor has released an advisory. Please see the references for more information.
Solution:
The vendor has released an advisory. Please see the references for more information.
References
Computer Associates ARCserve Backup Discovery Service Remote Denial Of Service Vulnerability
References:
References:
- ARCserve Backup Homepage (Computer Associates)
- carcbackazz-adv.txt (Luigi Auriemma)
- CA ARCserve Backup Discovery Service Denial of Service Vulnerability ("Williams, James K"
) - CA ARCserve Discovery Service casdscsvc denial of service vulnerability (Computer Associates)