Multiple Computer Associates (CA) Alert Notification Server buffer overflows

ca-alert-notification-bo (35467) The risk level is classified as HighHigh Risk

Description:

The CA BrightStor ARCserve Backup, BrightStor Enterprise Backup, BrightStor ARCserve Client agent, Threat Manager for the Enterprise, and Protection Suites are vulnerable to a buffer overflow, caused by improper bounds checking by the Alert Notification Server. By sending a specially-crafted RPC request, a remote attacker could overflow a buffer and execute arbitrary code on the system with SYSTEM or root privileges.

Note: Some systems require authentication to exploit this vulnerability

Platforms Affected:

  • CA, Anti-Virus for the Enterprise 8
  • CA, BrightStor ARCserve Backup 11.1
  • CA, BrightStor ARCserve Backup 11.5
  • CA, BrightStor ARCserve Backup 9.01
  • CA, BrightStor ARCserve Backup for Windows 11
  • CA, BrightStor Enterprise Backup 10.5
  • CA, Protection Suites 3.0
  • CA, Threat Manager 8 Enterprise

Remedy:

Refer to the CA SupportConnect document dated July 17th, 2007 "Security Notice for CA products running the Alert service" for patch, upgrade, or suggested workaround information. See References.

Consequences:

Gain Access

References:

  • CA SupportConnect July 17th, 2007, Security Notice for CA products running the Alert service at http://supportconnectw.ca.com/public/antivirus/infodocs/caantivirus-secnotice.asp.
  • iDefense Labs PUBLIC ADVISORY: 07.17.07, Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities at http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=561.
  • BID-24947: Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities
  • CVE-2007-3825: Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certain data to unspecified RPC procedures.
  • SA26088: CA Products Alert Notification Server Multiple Buffer Overflows
  • SECTRACK ID: 1018402: CA Threat Manager Stack Overflows in Alert Notification Service Let Remote Users Execute Arbitrary Code
  • SECTRACK ID: 1018403: CA Server Protection Suite Stack Overflows in Alert Notification Service Let Remote Users Execute Arbitrary Code
  • SECTRACK ID: 1018404: CA Business Protection Suite Stack Overflows in Alert Notification Service Let Remote Users Execute Arbitrary Code
  • SECTRACK ID: 1018405: BrightStor Enterprise Backup Stack Overflows in Alert Notification Service Let Remote Users Execute Arbitrary Code
  • SECTRACK ID: 1018406: BrightStor ARCserve Stack Overflows in Alert Notification Service Let Remote Users Execute Arbitrary Code
  • VUPEN/ADV-2007-2559: CA Products Alert Service RPC Interface Multiple Buffer Overflow Vulnerabilities

Reported:

Jul 17, 2007

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page