---------------------------------------------------------------------- A new version (0.9.0.0 - Release Candidate 1) of the free Secunia PSI has been released. The new version includes many new and advanced features, which makes it even easier to stay patched. Download and test it today: https://psi.secunia.com/ Read more about this new version: https://psi.secunia.com/?page=changelog ---------------------------------------------------------------------- TITLE: CA Products Alert Notification Server Multiple Vulnerabilities SECUNIA ADVISORY ID: SA29665 VERIFY ADVISORY: http://secunia.com/advisories/29665/ CRITICAL: Less critical IMPACT: DoS, System access WHERE: >From local network SOFTWARE: eTrust Antivirus 7.x http://secunia.com/product/2198/ CA Threat Manager 8.x http://secunia.com/product/7112/ CA Anti-Virus for the Enterprise 8.x http://secunia.com/product/10672/ BrightStor ARCserve Backup 11.x (for Windows) http://secunia.com/product/3099/ BrightStor ARCserve Backup 11.x (for Oracle) http://secunia.com/product/8147/ BrightStor ARCserve Backup 11.x (for Open Files) http://secunia.com/product/8250/ BrightStor ARCserve Backup 11.x (for Microsoft SQL Server) http://secunia.com/product/8144/ BrightStor ARCserve Backup 11.x http://secunia.com/product/312/ DESCRIPTION: Some vulnerabilities have been reported in various CA products, which can be exploited by malicious users to cause a DoS (Denial of Service) or to compromise a vulnerable system. The vulnerabilities are caused due to boundary errors within multiple procedures in the CA Alert Notification Server service, which can be exploited to cause buffer overflows. Successful exploitation allows execution of arbitrary code, but requires valid user credentials. The vulnerabilities are reported in the following products: * CA Anti-Virus for the Enterprise 7.1 * CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) r8 * CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) r8.1 * CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8 * CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8.1 * BrightStor ARCserve Backup r11.5 * BrightStor ARCserve Backup r11.1 * BrightStor ARCserve Backup r11 for Windows SOLUTION: Apply updates. CA Anti-Virus for the Enterprise 7.1, CA Anti-Virus for the Enterprise r8: Apply QO96079. https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=QO96079 CA Threat Manager for the Enterprise r8: Apply QO96387. https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=QO96387 CA Anti-Virus for the Enterprise r8.1, CA Threat Manager for the Enterprise r8.1: Apply QO96080. https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=QO96080 BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1: Apply QO96079. https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=QO96079 BrightStor ARCserve Backup r11.0: Upgrade to 11.1 and apply the latest patches. PROVIDED AND/OR DISCOVERED BY: The vendor credits an anonymous researcher working with iDefense VCP. ORIGINAL ADVISORY: https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=173103 http://community.ca.com/blogs/casecurityresponseblog/archive/2008/04/04/ca-alert-notification-server-multiple-vulnerabilities.aspx ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------