APP: Computer Associates Products Message Engine RPC Server Remote Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Computer Associates Products Message Engine. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the service.

Extended Description

Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.

Affected Products

Broadcom business_protection_suite

Short Name
APP:CA:RPC-MSG-BO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
Associates Buffer CVE-2006-5143 CVE-2007-0169 CVE-2009-1761 Computer Engine Message Overflow Products RPC Remote Server bid:20365 bid:22005 bid:35396
Release Date
06/14/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
Port
TCP/6503
False Positive
Unknown
Vendors

Broadcom

CVSS Score

7.5

5.0

Found a potential security threat?