CVE-2007-3216

Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote attackers to execute arbitrary code via crafted arguments to the (1) rxsAddNewUser, (2) rxsSetUserInfo, (3) rxsRenameUser, (4) rxsSetMessageLogSettings, (5) rxsExportData, (6) rxsSetServerOptions, (7) rxsRenameFile, (8) rxsACIManageSend, (9) rxsExportUser, (10) rxsImportUser, (11) rxsMoveUserData, (12) rxsUseLicenseIni, (13) rxsLicGetSiteId, (14) rxsGetLogFileNames, (15) rxsGetBackupLog, (16) rxsBackupComplete, (17) rxsSetDataProtectionSecurityData, (18) rxsSetDefaultConfigName, (19) rxsGetMessageLogSettings, (20) rxsHWDiskGetTotal, (21) rxsHWDiskGetFree, (22) rxsGetSubDirs, (23) rxsGetServerDBPathName, (24) rxsSetServerOptions, (25) rxsDeleteFile, (26) rxsACIManageSend, (27) rxcReadBackupSetList, (28) rxcWriteConfigInfo, (29) rxcSetAssetManagement, (30) rxcWriteFileListForRestore, (31) rxcReadSaveSetProfile, (32) rxcInitSaveSetProfile, (33) rxcAddSaveSetNextAppList, (34) rxcAddSaveSetNextFilesPathList, (35) rxcAddNextBackupSetIncWildCard, (36) rxcGetRevisions, (37) rxrAddMovedUser, (38) rxrSetClientVersion, or (39) rxsSetDataGrowthScheduleAndFilter commands.
References
Link Resource
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=599
http://osvdb.org/35329
http://research.eeye.com/html/advisories/published/AD20070920.html
http://research.eeye.com/html/advisories/upcoming/20070604.html
http://secunia.com/advisories/25606 Vendor Advisory
http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/bsabld-securitynotice.asp
http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/caarcservebld-securitynotice.asp
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=156006 Vendor Advisory
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35673 Vendor Advisory
http://www.securityfocus.com/archive/1/480252/100/100/threaded
http://www.securityfocus.com/bid/24348
http://www.securitytracker.com/id?1018216
http://www.securitytracker.com/id?1018728
http://www.vupen.com/english/advisories/2007/2121 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34805
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=599
http://osvdb.org/35329
http://research.eeye.com/html/advisories/published/AD20070920.html
http://research.eeye.com/html/advisories/upcoming/20070604.html
http://secunia.com/advisories/25606 Vendor Advisory
http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/bsabld-securitynotice.asp
http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/caarcservebld-securitynotice.asp
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=156006 Vendor Advisory
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35673 Vendor Advisory
http://www.securityfocus.com/archive/1/480252/100/100/threaded
http://www.securityfocus.com/bid/24348
http://www.securitytracker.com/id?1018216
http://www.securitytracker.com/id?1018728
http://www.vupen.com/english/advisories/2007/2121 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34805
Configurations

Configuration 1 (hide)

cpe:2.3:a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:32

Type Values Removed Values Added
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=599 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=599 -
References () http://osvdb.org/35329 - () http://osvdb.org/35329 -
References () http://research.eeye.com/html/advisories/published/AD20070920.html - () http://research.eeye.com/html/advisories/published/AD20070920.html -
References () http://research.eeye.com/html/advisories/upcoming/20070604.html - () http://research.eeye.com/html/advisories/upcoming/20070604.html -
References () http://secunia.com/advisories/25606 - Vendor Advisory () http://secunia.com/advisories/25606 - Vendor Advisory
References () http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/bsabld-securitynotice.asp - () http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/bsabld-securitynotice.asp -
References () http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/caarcservebld-securitynotice.asp - () http://supportconnectw.ca.com/public/sams/lifeguard/infodocs/caarcservebld-securitynotice.asp -
References () http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=156006 - Vendor Advisory () http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=156006 - Vendor Advisory
References () http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35673 - Vendor Advisory () http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35673 - Vendor Advisory
References () http://www.securityfocus.com/archive/1/480252/100/100/threaded - () http://www.securityfocus.com/archive/1/480252/100/100/threaded -
References () http://www.securityfocus.com/bid/24348 - () http://www.securityfocus.com/bid/24348 -
References () http://www.securitytracker.com/id?1018216 - () http://www.securitytracker.com/id?1018216 -
References () http://www.securitytracker.com/id?1018728 - () http://www.securitytracker.com/id?1018728 -
References () http://www.vupen.com/english/advisories/2007/2121 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/2121 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34805 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/34805 -

Information

Published : 2007-06-14 22:30

Updated : 2024-11-21 00:32


NVD link : CVE-2007-3216

Mitre link : CVE-2007-3216

CVE.ORG link : CVE-2007-3216


JSON object : View

Products Affected

broadcom

  • brightstor_arcserve_backup_laptops_desktops
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer