Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Multiple Computer Associates software products security vulnerabilities

  LS-20060220 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability

  LS-20060330 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability

  [Full-disclosure] [CAID 34693, 34694]: CA BrightStor ARCserve Backup Multiple Buffer Overflow Vulnerabilities

  [Full-disclosure] TSRT-06-11: CA Multiple Product DBASVR RPC Server Multiple Buffer Overflow Vulnerabilities

From:advisories_(at)_lssec.com <advisories_(at)_lssec.com>
Date:07.10.2006
Subject:LS-20060313 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability

Overview:
LSsec has discovered a vulnerability in Computer Associates BrightStor ARCserve Backup, which could be exploited by an anonymous attacker in order to execute arbitrary code with SYSTEM privileges on an affected system. The flaw specifically exists within the Message Engine (msgeng.exe) due to incorrect handling of RPC requests on TCP port 6503. The interface is identified by
dc246bf0-7a7a-11ce-9f88-00805fe43838. Opnum 43 specifies the vulnerable operation within this interface.

Advisory:

http://www.lssec.com/advisories/LS-20060313.pdf

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru