[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] ZDI-07-069: CA BrightStor ARCserve Backup Message Engine Insecure Method Expos
- To: <full-disclosure@xxxxxxxxxxxxxxxxx>, <bugtraq@xxxxxxxxxxxxxxxxx>
- Subject: Re: [Full-disclosure] ZDI-07-069: CA BrightStor ARCserve Backup Message Engine Insecure Method Expos
- From: "cocoruder." <frankruder@xxxxxxxxxxx>
- Date: Wed, 28 Nov 2007 03:32:51 +0000
it is so amazing that the vendor's advisory has been released more than one
month ago, (see my advisory of a similar vul at
http://ruder.cdut.net/blogview.asp?logID=221), and another thing is that I have
tested my reported vul again after CA's patch released one month ago, but in
fact they have not fixed it!! I report it again to CA but there is no response,
I guess CA is making an international joke with us:), or because this product
is sooooooooo bad that they will not support it any more?
welcome to my blog:http://ruder.cdut.net
> From: zdi-disclosures@xxxxxxxx> To: full-disclosure@xxxxxxxxxxxxxxxxx;
> bugtraq@xxxxxxxxxxxxxxxxx> Date: Mon, 26 Nov 2007 16:10:30 -0600> Subject:
> [Full-disclosure] ZDI-07-069: CA BrightStor ARCserve Backup Message Engine
> Insecure Method Exposure Vulnerability> > ZDI-07-069: CA BrightStor ARCserve
> Backup Message Engine Insecure Method > Exposure Vulnerability>
> http://www.zerodayinitiative.com/advisories/ZDI-07-069.html> November 26,
> 2007> > -- CVE ID:> CVE-2007-5328> > -- Affected Vendor:> Computer
> Associates> > -- Affected Products:> BrightStor ARCserve Backup r11.5>
> BrightStor ARCserve Backup r11.1> BrightStor ARCserve Backup r11.0>
> BrightStor Enterprise Backup r10.5> BrightStor ARCserve Backup v9.01> > --
> TippingPoint(TM) IPS Customer Protection:> TippingPoint IPS customers have
> been protected against this> vulnerability by Digital Vaccine protection
> filter ID 5144. > For further product information on the TippingPoint IPS:> >
> http://www.tippingpoint.com > > -- Vulnerabil
ity Details:> This vulnerability allows attackers to arbitrarily access and
modify the> file system and registry of vulnerable installations of Computer>
Associates BrightStor ARCserve Backup. Authentication is not required> to
exploit this vulnerability.> > The specific flaws exists in the Message Engine
RPC service which> listens by default on TCP port 6504 with the following
UUID:> > 506b1890-14c8-11d1-bbc3-00805fa6962e> > The service exposes a number
of insecure method calls including: 0x17F,> 0x180, 0x181, 0x182, 0x183, 0x184,
0x185, 0x186, 0x187, 0x188, 0x189,> 0x18A, 0x18B, and 0x18C. Attackers can
leverage these methods to> manipulate both the file system and registry which
can result in a> complete system compromise.> > -- Vendor Response:> Computer
Associates has issued an update to correct this vulnerability.> More details
can be found at:> >
http://supportconnectw.ca.com/public/storage/infodocs/basb-secnotice.asp> > --
Disclosure Timeline:> 2007.01.12 - Vulnerabi
lity reported to vendor> 2007.11.26 - Coordinated public release of advisory>
> -- Credit:> This vulnerability was discovered by Tenable Network Security.> >
-- About the Zero Day Initiative (ZDI):> Established by TippingPoint, The Zero
Day Initiative (ZDI) represents > a best-of-breed model for rewarding security
researchers for responsibly> disclosing discovered vulnerabilities.> >
Researchers interested in getting paid for their security research> through the
ZDI can find more information and sign-up at:> >
http://www.zerodayinitiative.com> > The ZDI is unique in how the acquired
vulnerability information is used.> 3Com does not re-sell the vulnerability
details or any exploit code.> Instead, upon notifying the affected product
vendor, 3Com provides its> customers with zero day protection through its
intrusion prevention> technology. Explicit details regarding the specifics of
the> vulnerability are not exposed to any parties until an official vendor>
patch is publicly av
ailable. Furthermore, with the altruistic aim of> helping to secure a broader
user base, 3Com provides this vulnerability> information confidentially to
security vendors (including competitors)> who have a vulnerability protection
or mitigation product.> > CONFIDENTIALITY NOTICE: This e-mail message,
including any attachments,> is being sent by 3Com for the sole use of the
intended recipient(s) and> may contain confidential, proprietary and/or
privileged information.> Any unauthorized review, use, disclosure and/or
distribution by any > recipient is prohibited. If you are not the intended
recipient, please> delete and/or destroy all copies of this message regardless
of form and> any included attachments and notify 3Com immediately by contacting
the> sender via reply e-mail or forwarding to 3Com at postmaster@xxxxxxxxx >
_______________________________________________> Full-Disclosure - We believe
in it.> Charter: http://lists.grok.org.uk/full-disclosure-charter.html> Hosted
and sponsored by Secunia - http://secunia.com/
_________________________________________________________________
用 Live Search 搜尽天下资讯!
http://www.live.com/?searchOnly=true
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/