Title: BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow Vulnerability
Severity: CRITICAL
Description:
Computer Associates BrightStor ARCserve/Enterprise Backup products provide backup and restore protection for Windows, NetWare, Linux and UNIX servers as well as Windows, Mac OS X, Linux, UNIX, AS/400 and VMS client. ARCserve/Enterprise Backup products are designed to detect other instances running on the same LAN through the discovery service utility. The ServicePC makes up part of the discovery service functionality and communicates over TCP port 41523.
A remote buffer overflow vulnerability reportedly affects BrightStor ARCserve and ARCserve Enterprise. This issue is due to a failure of the application to securely copy data from the network. It should be noted that this issue is reportedly distinct from that outlined in BID 12522 (BrightStor ARCserve/Enterprise Backup UDP Probe Remote Buffer Overflow Vulnerability).
The problem presents itself specifically when a malicious message is sent to the ServicePC functionality of the affected application over TCP port 41523. Apparently the application fails to securely copy the malicious data, triggering an overflow condition.
It has been reported that a packet of approximately 4096 bytes size is sufficient to trigger this issue.
A remote attacker may execute arbitrary code on a vulnerable computer, potentially facilitating unauthorized superuser access. A denial of service condition may arise as well.
Affected Products:
- Computer Associates BrightStor ARCServe Backup for AIX 11.1.0
- Computer Associates BrightStor ARCServe Backup for HP 11.1.0
- Computer Associates BrightStor ARCServe Backup for Linux 11.1.0
- Computer Associates BrightStor ARCServe Backup for Linux 7.0.0
- Computer Associates BrightStor ARCServe Backup for Linux 9.0.0
- Computer Associates BrightStor ARCServe Backup for Linux Japanese 9.0.0
- Computer Associates BrightStor ARCServe Backup for Macintosh 11.1.0
- Computer Associates BrightStor ARCServe Backup for Mainframe Linux 11.1.0
- Computer Associates BrightStor ARCServe Backup for NetWare 11.1.0
- Computer Associates BrightStor ARCServe Backup for NetWare 9.0.0
- Computer Associates BrightStor ARCServe Backup for Solaris 11.1.0
- Computer Associates BrightStor ARCServe Backup for Tru64 11.1.0
- Computer Associates BrightStor ARCServe Backup for Windows 11.0.0
- Computer Associates BrightStor ARCServe Backup for Windows 11.1.0
- Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.0.0
- Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.1.0
- Computer Associates BrightStor ARCServe Backup for Windows 64 bit 9.0.1
- Computer Associates BrightStor ARCServe Backup for Windows 9.0.0 .0.1
- Computer Associates BrightStor ARCserve 2000 Backup Windows Japanese 0.0.0
- Computer Associates BrightStor Enterprise Backup 10.0.0
- Computer Associates BrightStor Enterprise Backup 10.5.0
- Computer Associates BrightStor Enterprise Backup for AIX 10.0.0
- Computer Associates BrightStor Enterprise Backup for AIX 10.5.0
- Computer Associates BrightStor Enterprise Backup for HP 10.5.0
- Computer Associates BrightStor Enterprise Backup for HPUX 10.0.0
- Computer Associates BrightStor Enterprise Backup for Mainframe Linux 10.0.0
- Computer Associates BrightStor Enterprise Backup for Solaris 10.0.0
- Computer Associates BrightStor Enterprise Backup for Solaris 10.5.0
- Computer Associates BrightStor Enterprise Backup for Tru64 10.5.0
- Computer Associates BrightStor Enterprise Backup for Windows 64 bit 10.5.0
References:
- Computer Associates: BrightStor ARCserve Backup Product Page
- Computer Associates: BrightStor ARCserve Backup for Windows Product Page
- Computer Associates: NT -DISCOVERY SERVICE - SECURITY UPDATE
- Metasploit Framework: Metasploit CA BrightStor Discovery Service SERVICEPC Overflow
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.