CA ARCserve Backup LGServer Service Vulnerability
RISK: Medium Risk
A vulnerability has been identified in CA ARCserve Backup for Laptops and Desktops, CA Desktop Management Suite and CA Protection Suites, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by an integer underflow error in the LGServer service when processing malformed requests sent to port 1900/TCP, which could be exploited by remote attackers to crash an affected service or execute arbitrary code.
Impact
- Denial of Service
- Remote Code Execution
System / Technologies affected
- CA ARCserve Backup for Laptops and Desktops r11.5
- CA ARCserve Backup for Laptops and Desktops r11.1 SP2
- CA ARCserve Backup for Laptops and Desktops r11.1 SP1
- CA ARCserve Backup for Laptops and Desktops r11.1
- CA ARCserve Backup for Laptops and Desktops r11.0
- CA Desktop Management Suite 11.2
- CA Desktop Management Suite 11.1
- CA Protection Suites r2
- CA Protection Suites 3.0
- CA Protection Suites 3.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
CA ARCserve Backup for Laptops and Desktops 11.1, 11.1 SP1, 11.1 SP2 - Upgrade to 11.1 SP2 and apply patch :
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO00912Apply patch for CA ARCserve Backup for Laptops and Desktops 11.5 :
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO00913Apply patch for CA Protection Suites 3.0 :
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO00912Apply patch for CA Protection Suites 3.1 :
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO00912CA Desktop Management Suite 11.2 - Upgrade to CA Desktop Management Suite 11.2 C1 and apply patch :
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO00913Apply patch for CA Desktop Management Suite 11.1 :
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO01150CA ARCserve Backup for Laptops and Desktops 11.0 - Upgrade to ARCserve Backup for Laptops and Desktops version 11.1 SP2 and apply the latest patches :
https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=QI85497
Vulnerability Identifier
Source
Related Link
Share with