J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1537
    posted: 11/06/09
  • NSM Daily Update #1537
    posted: 11/06/09
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1537
    posted: 11/06/09
  • Deep Inspection 5.1 and 5.2 #1435
    posted: 11/06/09
  • Deep Inspection 5.0, 5.3r4 and below #1132
    posted: 03/28/08 (04/01/08 for 5.0)
  • Antivirus
    posted: 11/05/09

Title: BrightStor ARCserve/Enterprise Backup UDP Probe Remote Buffer Overflow Vulnerability

Severity: CRITICAL

Description:

Computer Associates BrightStor ARCserve/Enterprise Backup products provide backup and restore protection for Windows, NetWare, Linux and UNIX servers as well as Windows, Mac OS X, Linux, UNIX, AS/400 and VMS client. ARCserve/Enterprise Backup products are designed to detect other instances running on the same LAN through the discovery service utility, which communicates through UDP probe requests over port 41524.

Various BrightStor ARCserve/Enterprise Backup products are prone to a remote buffer overflow vulnerability. This issue presents itself because the affected applications do not perform boundary checks prior to copying user-supplied data into sensitive process buffers.

The problem presents itself specifically when the affected application receives a malformed discovery service UDP packet. Apparently the discovery service copies the data stored in discovery service packets into a 1000 byte buffer, while the data itself can be up to 4096 bytes long.

It should be noted that the impact of this issue is increased as the affected process runs with 'Local System' privileges; on UNIX computers it runs as the superuser and on Microsoft Windows it runs with SYSTEM privileges.

A remote attacker may execute arbitrary code on a vulnerable computer to gain unauthorized superuser access to it. A denial of service condition may arise as well.

It should be noted that this issue was previously believed to be exploitable over TCP port 4096. It has now bee revealed that that was a separate issue from this one and is outlined in BID 12536 (BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability).

Affected Products:

  • Computer Associates BrightStor ARCServe Backup for NetWare 11.1.0
  • Computer Associates BrightStor ARCServe Backup for NetWare 9.0.0
  • Computer Associates BrightStor ARCServe Backup for Windows 11.0.0
  • Computer Associates BrightStor ARCServe Backup for Windows 11.1.0
  • Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.0.0
  • Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.1.0
  • Computer Associates BrightStor ARCServe Backup for Windows 64 bit 9.0.1
  • Computer Associates BrightStor ARCServe Backup for Windows 9.0.0 .0.1
  • Computer Associates BrightStor ARCserve 2000 Backup Windows Japanese 0.0.0
  • Computer Associates BrightStor Enterprise Backup 10.0.0
  • Computer Associates BrightStor Enterprise Backup 10.5.0
  • Computer Associates BrightStor Enterprise Backup for Windows 64 bit 10.5.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.