[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2009-1761

Date: (C)2009-06-16   (M)2017-08-18
 
CVSS Score: 5.0Access Vector: NETWORK
Exploitability Subscore: 10.0Access Complexity: LOW
Impact Subscore: 2.9Authentication: NONE
 Confidentiality: NONE
 Integrity: NONE
 Availability: PARTIAL











The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.

Reference:
SECTRACK-1022405
http://www.securityfocus.com/archive/1/archive/1/504348/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/504349/100/0/threaded
BID-35396
SECUNIA-35473
ADV-2009-1608
ca-arcserve-ascore-dos(51169)
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/06/15/ca20090615-01-ca-arcserve-backup-message-engine-denial-of-service-vulnerabilities.aspx
http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=209502
http://www.ivizsecurity.com/security-advisory-iviz-sr-09003.html
http://www.ivizsecurity.com/security-advisory-iviz-sr-09004.html

CWE    1
CWE-20

© 2013 SecPod Technologies