Title: Computer Associates BrightStor ARCserve/Enterprise Backup=20
Agents buffer overflow vulnerability

CA Vulnerability ID: 33239

Discovery Date: 2005-04-25

Disclosure Date: 2005-08-02

Discovered By: iDEFENSE

Impact: A remote attacker can execute arbitrary code with SYSTEM=20
privileges.

Summary: Computer Associates BrightStor ARCserve Backup and=20
BrightStor Enterprise Backup Agents for Windows contain a=20
stack-based buffer overflow vulnerability. The vulnerability may=20
allow remote attackers to execute arbitrary code with SYSTEM=20
privileges, or cause a denial of service condition. The buffer=20
overflow is the result of improper bounds checking performed on=20
data sent to port 6070.=20

Severity: Computer Associates has given this vulnerability a=20
High risk rating.

Affected Technologies: This vulnerability exists in the=20
following BrightStor ARCserve Backup and BrightStor Enterprise=20
Backup application agents:

BrightStor ARCserve Backup r11.1:
- BrightStor ARCserve Backup r11.1 Agent for SQL for Windows
- BrightStor ARCserve Backup r11.1 Agent for Oracle for Windows
- BrightStor ARCserve Backup r11.1 Agent for SAP R/3 for Windows
- BrightStor ARCserve Backup r11.1 Agent for Microsoft Exchange=20
Premium Add-on for Windows

BrightStor ARCserve Backup r11.0:
- BrightStor ARCserve Backup Release 11 Agent for SQL for Windows
- BrightStor ARCserve Backup Release 11 Agent for Oracle for=20
Windows
- BrightStor ARCserve Backup Release 11 Agent for SAP R/3 for=20
Windows
- BrightStor ARCserve Backup Release 11 Agent for Microsoft=20
Exchange Premium Add-on for Windows

BrightStor ARCserve Backup v9.01
- BrightStor ARCserve Backup Version 9 Agent for SQL for Windows
- BrightStor ARCserve Backup Version 9 Agent for Oracle for=20
Windows=20
- BrightStor ARCserve Backup Version 9 Agent for SAP R/3 for=20
Windows=20

BrightStor Enterprise Backup 10.5
- BrightStor Enterprise Backup v10.5 Agent for SQL for Windows
- BrightStor Enterprise Backup v10.5 Agent for Oracle for=20
Windows
- BrightStor Enterprise Backup v10.5 Serverless Backup Agent for=20
Oracle for Windows
- BrightStor Enterprise Backup v10.5 Agent for Oracle for EMC=20
Timefinder for Windows
- BrightStor Enterprise Backup v10.5 Agent for SAP R/3 for=20
NT/2000

BrightStor Enterprise Backup 10
- BrightStor Enterprise Backup Agent for SQL for Windows
- BrightStor Enterprise Backup Agent for Oracle for Windows
- BrightStor Enterprise Backup Agent for SAP R/3 for Oracle and=20
SQL on Windows
- BrightStor Enterprise Backup Agent for Oracle for EMC=20
Timefinder for Windows
- BrightStor Enterprise Backup Serverless Backup Agent for=20
Oracle for Windows

Status: Security updates that completely remediate this=20
vulnerability issue are available for all affected products.

Recommendation (note that URLs may wrap):=20
Apply the appropriate security update(s).
BrightStor ARCserve Backup r11.1 for Windows:
http://supportconnect.ca.com/sc/solc...rno=3DQO70767=
&
startsearch=3D1
BrightStor ARCserve Backup r11.0 for Windows:
http://supportconnect.ca.com/sc/solc...rno=3DQO70769=
&
startsearch=3D1
BrightStor ARCserve Backup v9.01 for Windows:
http://supportconnect.ca.com/sc/solc...rno=3DQO70770=
&
startsearch=3D1
BrightStor Enterprise Backup v10.5 for Windows:
http://supportconnect.ca.com/sc/solc...rno=3DQO70774=
&
startsearch=3D1
BrightStor Enterprise Backup v10.0 for Windows:
http://supportconnect.ca.com/sc/solc...rno=3DQO70773=
&
startsearch=3D1

CVE Reference: Pending

OSVDB Reference: Pending

Advisory URLs (note that URLs may wrap):=20

CA Security Advisor site
http://www3.ca.com/securityadvisor/v...spx?id=3D33239

E-News: BrightStor Storage Newsletter v05.11 August 2nd, 2005
http://supportconnectw.ca.com/public...brig080205.asp


Should you require additional information, please contact CA=20
Technical Support at http://supportconnect.ca.com.


Respectfully,

Ken Williams ; Dir. Vuln Research=20
Computer Associates ; 0xE2941985


Computer Associates International, Inc. (CA).=20
One Computer Associates Plaza. Islandia, NY 11749
=09
Contact Us http://ca.com/catalk.htm
Legal Notice http://ca.com/calegal.htm
Privacy Policy http://ca.com
Copyright 2005 Computer Associates International, Inc.
All rights reserved