PT-2007-1653 · Computer Associates · Ca Brightstor Arcserve Backup+2
Published
2007-01-11
·
Updated
2021-04-07
·
CVE-2007-0169
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Computer Associates (CA) BrightStor ARCserve Backup versions 9.01 through 11.5
Computer Associates (CA) Enterprise Backup version 10.5
Computer Associates (CA) Server/Business Protection Suite version r2
Description
The issue allows remote attackers to execute arbitrary code via RPC requests with crafted data for specific opnums in the Message Engine RPC service or the Tape Engine service. Specifically, the opnums affected are 0x2F, 0x75 in the Message Engine RPC service, and 0xCF in the Tape Engine service.
Recommendations
For Computer Associates (CA) BrightStor ARCserve Backup versions 9.01 through 11.5, update to a version outside of this range to mitigate the risk.
For Computer Associates (CA) Enterprise Backup version 10.5, update to a version outside of this range to mitigate the risk.
For Computer Associates (CA) Server/Business Protection Suite version r2, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the Message Engine RPC service and the Tape Engine service to minimize the risk of exploitation.
Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca Brightstor Arcserve Backup
Ca Enterprise Backup
Ca Server/Business Protection Suite