Vulnerability Name: | CVE-2006-5172 (CCN-29344) | ||||||||
Assigned: | 2006-10-04 | ||||||||
Published: | 2007-01-11 | ||||||||
Updated: | 2021-04-07 | ||||||||
Summary: | Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe String Handling Overflow," a different vulnerability than CVE-2006-5171. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-5172 Source: OSVDB Type: UNKNOWN 31320 Source: CCN Type: SA23648 CA BrightStor ARCserve Backup Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 23648 Source: CCN Type: SECTRACK ID: 1017506 BrightStor ARCserve Backup Bugs in Tape Engine, Mediasvr, and ASCORE.DLL Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1017506 Source: CCN Type: CA SupportConnect Web site Important Security Notice for BrightStor ARCserve Backup Source: CONFIRM Type: Exploit http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp Source: CCN Type: IBM Internet Security Systems Protection Advisory, Jan 11, 2006 Computer Associates Brightstor ARCserve Mediasvr.exe String Handling Overflow Source: ISS Type: UNKNOWN 20070111 Computer Associates Brightstor ARCserve Mediasvr.exe String Handling Overflow Source: CCN Type: OSVDB ID: 31319 CA BrightStor ARCserve Backup Mediasvr.exe RPC Remote Overflow Source: CCN Type: OSVDB ID: 31320 CA BrightStor ARCserve Backup Mediasvr.exe String Handling Overflow Source: BUGTRAQ Type: UNKNOWN 20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities Source: BID Type: UNKNOWN 22016 Source: CCN Type: BID-22016 Computer Associates BrightStor ARCserve Backup MediaSVR.EXE Variant Buffer Overflow Vulnerability Source: VUPEN Type: UNKNOWN ADV-2007-0154 Source: XF Type: UNKNOWN backup-product-string-overflow(29344) Source: XF Type: UNKNOWN backup-product-string-overflow(29344) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |