Skip to main content

CA BrightStor ARCserve Backup List Control Code Execution Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 18 Mar 2008 4458 Views

RISK: Medium Risk

A vulnerability has been identified in CA BrightStor ARCserve Backup, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the "ListCtrl.ocx" ActiveX Control when handling overly long arguments passed to the "AddColumn()" method, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • CA BrightStor ARCserve Backup r11.5

Solutions

There is no patch available for this vulnerability currently.

Workaround:
Set a kill bit for the CLSID {BF6EFFF3-4558-4C4C-ADAF-A87891C5F3A3}.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link