Overview
Multiple Computer Associates products contain a buffer overflow in the code that handles the Discovery Service protocol. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code.
Description
Computer Associates BrightStor ARCserve Backup, BrightStor Enterprise Backup, CA Server Protection Suite, and CA Business Protection Suite software use a protocol known as the Discovery Service to find other BrightStor and Protection Suite installations. A lack of validation on Discovery Service packets may allow a buffer overflow to occur. This vulnerability only affects Computer Associates BrightStor ARCserve and Protection Suite products for the Microsoft Windows platform. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code with SYSTEM privileges. |
Solution
Upgrade |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.tippingpoint.com/security/advisories/TSRT-06-11.html
- http://www.zerodayinitiative.com/advisories/ZDI-06-030.html
- http://www.zerodayinitiative.com/advisories/ZDI-06-031.html
- http://www.lssec.com/advisories/LS-20060220.pdf
- http://www.lssec.com/advisories/LS-20060313.pdf
- http://www.lssec.com/advisories/LS-20060330.pdf
- http://supportconnectw.ca.com/public/storage/infodocs/basbr-secnotice.asp
- http://www3.ca.com/securityadvisor/blogs/posting.aspx?pid=93775&id=90744
- http://www3.ca.com/securityadvisor/blogs/posting.aspx?pid=94397&id=90744
- http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34693
- http://www.securityfocus.com/bid/20365
- http://www.frsirt.com/english/advisories/2006/3930
- http://securitytracker.com/id?1017003
- http://securitytracker.com/id?1017004
- http://securitytracker.com/id?1017005
- http://securitytracker.com/id?1017006
- http://xforce.iss.net/xforce/xfdb/29364
Acknowledgements
This vulnerability was reported by the TippingPoint and the Zero Day Initiative. TippingPoint credits LSsecurity with reporting this vulnerability.
This document was written by Jeff Gennari based on information from LSsecurity.
Other Information
CVE IDs: | CVE-2006-5143 |
Severity Metric: | 16.54 |
Date Public: | 2006-10-05 |
Date First Published: | 2006-11-01 |
Date Last Updated: | 2007-01-12 21:37 UTC |
Document Revision: | 33 |