Thread-topic: [SA22285] CA Products Multiple Buffer Overflow Vulnerabilities
>
> TITLE:
> CA Products Multiple Buffer Overflow Vulnerabilities
>
> SECUNIA ADVISORY ID:
> SA22285
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Moderately critical
>
> IMPACT:
> System access
>
> WHERE:
> From local network
>
> SOFTWARE:
> CA Server Protection Suite r2
>
> CA Business Protection Suite r2
>
> CA Business Protection Suite for Microsoft Small Business Server
> Standard Edition r2
>
> CA Business Protection Suite for Microsoft Small Business Server
> Premium Edition r2
>
> BrightStor Enterprise Backup 10.x
>
> BrightStor ARCserve Backup 9.x
>
> BrightStor ARCserve Backup 11.x (for Windows)
>
> BrightStor ARCserve Backup 11.x
>
>
> DESCRIPTION:
> Some vulnerabilities have been reported in various CA products, which
> can be exploited by malicious people to compromise a vulnerable
> system.
>
> 1) Some boundary errors exist within RPC routines in the Backup Agent
> RPC Server (DBASRV.exe), which can be exploited to cause stack-based
> buffer overflows and allow arbitrary code execution.
>
> 2) A boundary error exists in ASBRDCST.DLL when processing Discovery
> Service communication. This can be exploited to cause a stack-based
> buffer overflow and allows execution of arbitrary code.
>
> 3) Two boundary errors exist within RPC routines in ASCORE.dll, used
> by the Message Engine RPC Server. These can be exploited to cause a
> heap-based buffer overflow and a stack-based buffer overflow by
> passing an overly long string as the second parameter, and allow
> arbitrary code execution.
>
> The following products for the Windows platform are affected:
> * BrightStor ARCserve Backup r11.5 SP1 and below (SP2 is not
> affected)
> * BrightStor ARCserve Backup r11.1
> * BrightStor ARCserve Backup for Windows r11
> * BrightStor Enterprise Backup 10.5
> * BrightStor ARCserve Backup v9.01
> * CA Server Protection Suite r2
> * CA Business Protection Suite r2
> * CA Business Protection Suite for Microsoft Small Business Server
> Standard Edition r2
> * CA Business Protection Suite for Microsoft Small Business Server
> Premium Edition r2
>
> SOLUTION:
> Update to the latest version.
>
>
> PROVIDED AND/OR DISCOVERED BY:
> 1) Pedram Amini, TippingPoint Security Research Team
> 2,3) livesploit.com
>
> ORIGINAL ADVISORY:
> 1) TippingPoint:
>
>
> 2,3) Zero Day Initiative:
>
>
>
> CA:
>
> cnotice.asp
>