Title: Computer Associates BrightStor ARCserve Backup UniversalAgent Remote Buffer Overflow Vulnerability
Severity: CRITICAL
Description:
Computer Associates BrightStor ARCserve/Enterprise Backup products provide backup and restore protection for Windows, NetWare, Linux, and UNIX servers as well as Windows, Mac OS X, Linux, UNIX, AS/400, and VMS clients. The BrightStor ARCserve agent performs backup procedures on network nodes.
A remote buffer-overflow vulnerability affects BrightStor ARCserve and ARCserve Enterprise agent because the application fails to securely copy data from the network.
The problem presents itself specifically when handling a malicious message that includes a superfluous string value and a subsequent 'option' field value of 0, 3, or 1000. Apparently, the application fails to securely copy the malicious data, triggering an overflow condition.
A remote attacker may exploit this issue to execute arbitrary code on a vulnerable computer, potentially facilitating unauthorized superuser access. A denial-of-service condition may arise as well.
BrightStor ARCserve Backup v11 for Win32 platforms is vulnerable; other versions may also be affected.
Affected Products:
- Computer Associates BrightStor ARCServe Backup for Windows 11.0.0
- Computer Associates BrightStor ARCServe Backup for Windows 11.1.0
- Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.0.0
- Computer Associates BrightStor ARCServe Backup for Windows 64 bit 11.1.0
- Computer Associates BrightStor ARCServe Backup for Windows 64 bit 9.0.1
- Computer Associates BrightStor ARCServe Backup for Windows 9.0.0 .0.1
- Computer Associates BrightStor ARCserve Backup for Windows (All) 11.1
- Computer Associates BrightStor ARCserve Backup for Windows (Client) 11.1
- Computer Associates BrightStor ARCserve Backup for Windows (Eng-All) 9.01
- Computer Associates BrightStor ARCserve Backup for Windows (Eng-Cli) 9.01
- Computer Associates BrightStor ARCserve Backup for Windows (NoEng-All) 9.01
- Computer Associates BrightStor ARCserve Backup for Windows (NoEng-Cli) 9.01
- Computer Associates BrightStor Enterprise Backup 10.0.0
- Computer Associates BrightStor Enterprise Backup 10.5.0
- Computer Associates BrightStor Enterprise Backup for Windows 64 bit 10.5.0
References:
- Computer Associates: BrightStor ARCserve Backup for Windows Product Page
- iDEFENSE: Computer Associates BrightStor ARCserve Backup UniversalAgent Buffer Overflow
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.