Vulnerability Name:

CVE-2006-0306 (CCN-24166)

Assigned:2006-01-17
Published:2006-01-17
Updated:2021-04-13
Summary:The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Full-Disclosure Mailing List, Tue Jan 17 2006 - 08:03:23 CST
DM Primer error handling weakness & an old CAM BO revisited

Source: CCN
Type: Ful- Disclosure Mailing List, Wed Jan 18 2006 - 09:42:57 CST
CAID 33756 - DM Deployment Common Component Vulnerabilities

Source: MITRE
Type: CNA
CVE-2006-0306

Source: MITRE
Type: CNA
CVE-2006-0307

Source: CCN
Type: SA18531
CA DM Deployment Common Component Denial of Service

Source: SECUNIA
Type: Vendor Advisory
18531

Source: CCN
Type: SECTRACK ID: 1015504
DM Deployment Common Component (DMPrimer) Lets Remote Users Deny Service

Source: SECTRACK
Type: UNKNOWN
1015504

Source: CCN
Type: DM Deployment Common Component Security Notice, January 17, 2006
DM Deployment Common Component Vulnerabilities.

Source: CONFIRM
Type: Vendor Advisory
http://supportconnectw.ca.com/public/ca_common_docs/dmdeploysecurity_notice.asp

Source: MISC
Type: Vendor Advisory
http://www.designfolks.com.au/karma/DMPrimer/

Source: OSVDB
Type: UNKNOWN
22529

Source: CCN
Type: OSVDB ID: 22529
CA Multiple Products Crafted Traffic DM Primer DoS

Source: CCN
Type: OSVDB ID: 22530
CA Multiple Products DM Primer Crafted UDP Packet WSAEMESGSIZE Error Condition DoS

Source: BUGTRAQ
Type: UNKNOWN
20060118 CAID 33756 - DM Deployment Common Component Vulnerabilities

Source: BID
Type: Exploit
16276

Source: CCN
Type: BID-16276
Computer Associates Unicenter Remote Control DM Primer Remote Denial of Service Vulnerability

Source: VUPEN
Type: Vendor Advisory
ADV-2006-0236

Source: CONFIRM
Type: Vendor Advisory
http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=33756

Source: XF
Type: UNKNOWN
ca-unicenter-dmprimer-dos(24166)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:broadcom:brightstor_mobile_backup:r4.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:business_protection_suite:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ca:unicenter_remote_control:6.0_build_6.0.56.3:*:*:en:*:*:*:*
  • OR cpe:/a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:de:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:unicenter_remote_control:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:unicenter_remote_control:6.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.1:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup_laptops_desktops:11.1:sp1:*:*:*:*:*:*
  • OR cpe:/a:ca:unicenter_remote_control:6.0:sp1:*:en:*:*:*:*
  • OR cpe:/a:ca:unicenter_remote_control:6.0:sp1:*:fr:*:*:*:*
  • OR cpe:/a:broadcom:desktop_protection_suite:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:server_protection_suite:2:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:unicenter_remote_control:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:en:*:*:*:*
  • OR cpe:/a:ca:unicenter_remote_control:6.0_build_6.0.74:*:*:fr:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:broadcom:unicenter_remote_control:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:unicenter_remote_control:6.0:sp1:*:*:*:*:*:*
  • AND
  • cpe:/a:ca:brightstor_arcserve_backup:11.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:*
  • OR cpe:/a:ca:brightstor_arcserve_backup:11.1::sp1:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_mobile_backup:r4.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:desktop_protection_suite:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:server_protection_suite:2:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:business_protection_suite:2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    broadcom brightstor mobile backup r4.0
    broadcom business protection suite 2.0
    ca unicenter remote control 6.0_build_6.0.56.3
    ca unicenter remote control 6.0_build_6.0.74
    broadcom brightstor arcserve backup laptops desktops 11.0
    broadcom unicenter remote control 6.0
    broadcom unicenter remote control 6.0 sp1
    broadcom brightstor arcserve backup laptops desktops 11.1
    broadcom brightstor arcserve backup laptops desktops 11.1 sp1
    ca unicenter remote control 6.0 sp1
    ca unicenter remote control 6.0 sp1
    broadcom desktop protection suite 2.0
    broadcom server protection suite 2
    broadcom unicenter remote control 5.2
    ca unicenter remote control 6.0_build_6.0.74
    ca unicenter remote control 6.0_build_6.0.74
    ca unicenter remote control 6.0
    ca unicenter remote control 6.0 sp1
    ca brightstor arcserve backup 11.0
    ca brightstor arcserve backup 11.1
    ca brightstor arcserve backup 11.1
    ca brightstor mobile backup r4.0
    ca desktop protection suite 2.0
    ca server protection suite 2
    ca business protection suite 2.0