---------------------------------------------------------------------- Secunia is pleased to announce the release of the annual Secunia report for 2008. Highlights from the 2008 report: * Vulnerability Research * Software Inspection Results * Secunia Research Highlights * Secunia Advisory Statistics Request the full 2008 Report here: http://secunia.com/advisories/try_vi/request_2008_report/ Stay Secure, Secunia ---------------------------------------------------------------------- TITLE: CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities SECUNIA ADVISORY ID: SA34920 VERIFY ADVISORY: http://secunia.com/advisories/34920/ DESCRIPTION: Some vulnerabilities have been reported in CA ARCserve Backup, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service). The vulnerabilities are caused due to the usage of a vulnerable version of Apache HTTP Server. For more information: SA8499 SA12540 The vulnerabilities are reported in CA ARCserve Backup r11.5 for Solaris, Tru64, HP-UX, and AIX. SOLUTION: Apply the patches. CA ARCserve Backup r11.5 Solaris: RO06786 https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO06786 CA ARCserve Backup r11.5 Tru64: RO06788 https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO06788 CA ARCserve Backup r11.5 HP-UX: RO06789 https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO06789 CA ARCserve Backup r11.5 AIX: RO06791 https://support.ca.com/irj/portal/anonymous/redirArticles?reqPage=search&searchID=RO06791 PROVIDED AND/OR DISCOVERED BY: For reporting the vulnerabilities in CA ARCserve Backup the vendor credits: * Apache Software Foundation * David Endler of iDefense * Ulf Harnhammar for SITIC, Swedish IT Incident Centre ORIGINAL ADVISORY: CA20090429-01: https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=205147 OTHER REFERENCES: SA8499: http://secunia.com/advisories/8499/ SA12540: http://secunia.com/advisories/12540/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------