Overview
The Computer Associates BrightStor ARCserve Backup contains a buffer overflow in the handling of RPC data that may allow a remote attacker to execute arbitrary code.
Description
BrightStor ARCserve Backup is a backup and data retention tool that integrates with other BrightStor Data Availability and BrightStor Storage Management solutions. A vulnerability exists in Mediasrv.exe which is a component of BrightStor ARCserve Backup Tape Engine. The Tape Engine features allow BrightStor ARCserve Backup products to use tape drives for storage. This vulnerability may be exploited by sending a specially crafted RPC request to a vulnerable system. According to Shirkdog Security Advisory SHK-004: |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code. |
Solution
Update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This issue was publicly reported in Shirkdog Security Advisory SHK-004.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2007-1785 |
Severity Metric: | 27.56 |
Date Public: | 2007-03-29 |
Date First Published: | 2007-04-02 |
Date Last Updated: | 2007-05-10 14:06 UTC |
Document Revision: | 20 |