Computer Associates ARCserve Backup CVE-2012-1662 Denial of Service Vulnerability
BID:52655
Info
Computer Associates ARCserve Backup CVE-2012-1662 Denial of Service Vulnerability
| Bugtraq ID: | 52655 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-1662 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2012 12:00AM |
| Updated: | Mar 21 2012 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Computer Associates ARCserve Backup R16 Computer Associates ARCserve Backup r15 SP1 Computer Associates ARCserve Backup r15 Computer Associates ARCserve Backup r12.5 SP1 Computer Associates ARCserve Backup r12.0 SP2 Computer Associates ARCserve Backup r12.0 sp1 Computer Associates ARCserve Backup 12.5 Computer Associates ARCserve Backup 12.0 |
| Not Vulnerable: |
Computer Associates ARCserve Backup r16 SP1 Computer Associates ARCserve Backup r12.5 SP2 |
Discussion
Computer Associates ARCserve Backup CVE-2012-1662 Denial of Service Vulnerability
Computer Associates ARCserve Backup is prone to an unspecified denial-of-service vulnerability because it fails to properly handle user-supplied input.
Attackers can exploit this issue to crash the affected application, denying service to legitimate users.
The following applications are affected:
CA ARCserve Backup for Windows r12.0, r12.0 SP1, r12.0 SP2
CA ARCserve Backup for Windows r12.5, r12.5 SP1
CA ARCserve Backup for Windows r15, r15 SP1
CA ARCserve Backup for Windows r16
Computer Associates ARCserve Backup is prone to an unspecified denial-of-service vulnerability because it fails to properly handle user-supplied input.
Attackers can exploit this issue to crash the affected application, denying service to legitimate users.
The following applications are affected:
CA ARCserve Backup for Windows r12.0, r12.0 SP1, r12.0 SP2
CA ARCserve Backup for Windows r12.5, r12.5 SP1
CA ARCserve Backup for Windows r15, r15 SP1
CA ARCserve Backup for Windows r16
Exploit / POC
Computer Associates ARCserve Backup CVE-2012-1662 Denial of Service Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Computer Associates ARCserve Backup CVE-2012-1662 Denial of Service Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Solution:
The vendor has released an advisory and updates. Please see the references for details.
References
Computer Associates ARCserve Backup CVE-2012-1662 Denial of Service Vulnerability
References:
References:
- Computer Associates Homepage (Computer Associates)
- CA20120320-01: Security Notice for CA ARCserve Backup (Computer Associates)