Full Disclosure mailing list archives
LS-20061113 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability
From: advisories () lssec com
Date: Tue, 21 Nov 2006 18:32:15 +0100 (CET)
LS-20061113 LSsec has discovered a vulnerability in Computer Associates BrightStor ARCserve Backup v11.5, which could be exploited by an anonymous attacker in order to execute arbitrary code with SYSTEM privileges on an affected system. The flaw specifically exists within the Tape Engine (tapeeng.exe) due to incorrect handling of RPC requests on TCP port 6502. For technical details please visit: http://www.lssec.com/charity.html LSsecurity - LSsec.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- LS-20061113 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability advisories (Nov 21)
- <Possible follow-ups>
- Re: LS-20061113 - CA BrightStor ARCserve Backup Remote Buffer Overflow Vulnerability Williams, James K (Nov 21)