Vulnerability Name:

CVE-2007-1785 (CCN-33316)

Assigned:2007-03-29
Published:2007-03-29
Updated:2021-04-07
Summary:The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C)
5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Fri Mar 30 2007 - 19:59:12 CDT
CA BrightStor ARCserve Backup Mediasvr.exe vulnerability

Source: CCN
Type: Full-Disclosure Mailing List, Thu Mar 29 2007 - 20:30:00 CDT
CA Brightstor Backup Mediasvr.exe Remote Code Vulnerability

Source: FULLDISC
Type: UNKNOWN
20070329 CA Brightstor Backup Mediasvr.exe Remote Code Vulnerability

Source: MITRE
Type: CNA
CVE-2007-1785

Source: CCN
Type: SA24682
CA BrightStor ARCserve Backup MEDIASVR.EXE RPC Request Code Execution

Source: SECUNIA
Type: Vendor Advisory
24682

Source: SREASON
Type: UNKNOWN
2509

Source: CCN
Type: SECTRACK ID: 1017830
CA BrightStor Backup Buffer Overflow in Mediasvr.exe Lets Remote Users Execute Arbitrary Code

Source: CCN
Type: CA SupportConnect
BrightStor ARCserve Backup Media Server Security Notice

Source: CONFIRM
Type: UNKNOWN
http://supportconnectw.ca.com/public/storage/infodocs/babmedser-secnotice.asp

Source: CCN
Type: US-CERT VU#151305
CA Brightstor ARCserve Backup fails to properly process RPC requests

Source: CERT-VN
Type: US Government Resource
VU#151305

Source: CCN
Type: OSVDB ID: 34125
Cisco Multiple Products Online Help System PreSearch.class XSS

Source: BUGTRAQ
Type: UNKNOWN
20070330 CA Brightstor Backup Mediasvr.exe Remote Code Vulnerability

Source: BUGTRAQ
Type: UNKNOWN
20070331 CA BrightStor ARCserve Backup Mediasvr.exe vulnerability

Source: BID
Type: UNKNOWN
23209

Source: CCN
Type: BID-23209
Computer Associates BrightStor ARCserve Backup MediaSVR.EXE 191 Buffer Overflow Vulnerability

Source: SECTRACK
Type: UNKNOWN
1017830

Source: MISC
Type: UNKNOWN
http://www.shirkdog.us/camediasvrremote.py

Source: MISC
Type: UNKNOWN
http://www.shirkdog.us/shk-004.html

Source: VUPEN
Type: UNKNOWN
ADV-2007-1161

Source: CCN
Type: CA Brightstor ARCserve Backup Web site
BrightStor ARCserve Backup, Storage Management

Source: XF
Type: UNKNOWN
brightstor-mediasvr-bo(33316)

Source: XF
Type: UNKNOWN
brightstor-mediasvr-bo(33316)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ca:brightstor_arcserve_backup:11:*:windows:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:9.01:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:11.5:sp1:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:11.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:11.5:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ca:brightstor_arcserve_backup:11.0::windows:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_enterprise_backup:10.5:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:11.1:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:server_protection_suite:2:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:business_protection_suite:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:broadcom:brightstor_arcserve_backup:11.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ca brightstor arcserve backup 11
    broadcom brightstor arcserve backup 9.01
    broadcom brightstor arcserve backup 11.5 sp1
    broadcom brightstor arcserve backup 11.5 sp2
    broadcom brightstor arcserve backup 11.1
    broadcom brightstor arcserve backup 11.5
    ca brightstor arcserve backup 11.0
    ca brightstor enterprise backup 10.5
    ca brightstor arcserve backup 11.1
    ca server protection suite 2
    ca business protection suite 2.0
    ca brightstor arcserve backup 11.5