Vissza a www.andrews.hu-ra

    [guru] CA biztonsagi frissitesek


    DATE: Mon, 26 Jan 2009 22:13:36 +0100
    A CA ARCserve Backup egyik RPC függvénye tetszőleges kód futtatási
    lehetőséget tartalmaz.
    
    A CA Service Metric Analysis és CA Service Level Management termékek
    smmsnmpd szolgáltatása nem megfelelően ellenőrzi a hozzáférési jogokat,
    minek hatására a támadónak kód futtatásra nyílik lehetősége.
    
    
    --- Begin Message ---
    Title: CA ARCserve Backup LDBserver Vulnerability
    
    
    CA Advisory Date: 2008-12-10
    
    
    Reported By:
    Dyon Balding of Secunia Research
    
    
    Impact: A remote attacker can cause a denial of service or execute 
    arbitrary code.
    
    
    Summary: CA ARCserve Backup contains a vulnerability that can 
    allow a remote attacker to cause a denial of service or execute 
    arbitrary code. CA has issued patches to address the 
    vulnerability. The vulnerability, CVE-2008-5415, is due to 
    insufficient verification of client data. A remote attacker can 
    crash the LDBserver service or execute arbitrary code in the 
    context of the service. Note: The client installation is not 
    affected.
    
    
    Mitigating Factors: The client installation is not affected.
    
    
    Severity: CA has given this vulnerability a High risk rating.
    
    
    Affected Products:
    CA ARCserve Backup r12.0 Windows
    CA ARCserve Backup r11.5 Windows*
    CA ARCserve Backup r11.1 Windows*
    CA Server Protection Suite r2
    CA Business Protection Suite r2
    CA Business Protection Suite for Microsoft Small Business Server 
       Standard Edition r2
    CA Business Protection Suite for Microsoft Small Business Server 
       Premium Edition r2
    
    *Formerly known as BrightStor ARCserve Backup.
    
    
    Non-Affected Products
    CA ARCserve Backup r12.0 Windows SP1
    
    
    Affected Platforms:
    Windows
    
    
    Status and Recommendation:
    CA has issued the following patches to address the vulnerability.
    
    CA ARCserve Backup r12.0 Windows:
    Apply Service Pack 1 (RO01340)
    
    CA ARCserve Backup r11.5 Windows:
    RO04383
    
    CA ARCserve Backup r11.1 Windows:
    RO04382
    
    CA Protection Suites r2:
    RO04383
    
    
    How to determine if you are affected:
    
    CA ARCserve Backup r12.0 Windows,
    CA ARCserve Backup r11.5 Windows:
    
    1. Run the ARCserve Patch Management utility. From the Windows 
       Start menu, it can be found under:
       Programs > CA > ARCserve Patch Management > Patch Status
    
    2. The main patch status screen will indicate if the respective 
       patch in the below table is currently applied. If the patch is 
       not applied, the installation is vulnerable.
    
    Product                             Patch
    CA ARCserve Backup r12.0 Windows    RO01340
    CA ARCserve Backup r11.5 Windows*   RO04383
    
    For more information on the ARCserve Patch Management utility, 
    read document TEC446265.
    
    Alternatively, use the file information below to determine if the 
    product installation is vulnerable.
    
    CA ARCserve Backup r11.1 Windows:
    
    1. Using Windows Explorer, locate the file "DBserver.dll". By 
       default, the file is located in the 
       "C:\Program Files\CA\BrightStor ARCserve Backup" directory.
    
    2. Right click on the file and select Properties.
    
    3. Select the General tab.
    
    4. If the file timestamp is earlier than indicated in the table 
       below, the installation is vulnerable.
    
    Product version:  CA ARCserve Backup r11.1 Windows
    File Name:  DBserver.dll
    File Size:  675840 bytes
    Timestamp:  11/25/2008 09:32:21
    
    *CA Protection Suites r2 includes CA ARCserve Backup 11.5
    
    
    Workaround: None
    
    
    References (URLs may wrap):
    CA Support:
    http://support.ca.com/
    Security Notice for CA ARCserve Backup LDBserver
    https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=1942
    93
    Solution Document Reference APARs:
    RO01340, RO04383, RO04382
    CA Security Response Blog posting:
    CA ARCserve Backup LDBserver Vulnerability
    community.ca.com/blogs/casecurityresponseblog/archive/2008/12/10.aspx
    Reported By: 
    Dyon Balding of Secunia Research
    CVE References:
    CVE-2008-5415 - LDBserver code execution
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5415
    OSVDB References: Pending
    http://osvdb.org/
    
    
    Changelog for this advisory:
    v1.0 - Initial Release
    
    
    Customers who require additional information should contact CA
    Technical Support at http://support.ca.com.
    
    For technical questions or comments related to this advisory, 
    please send email to vuln AT ca DOT com.
    
    If you discover a vulnerability in CA products, please report your 
    findings to the CA Product Vulnerability Response Team.
    https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=1777
    82
    
    
    Regards,
    Ken Williams, Director ; 0xE2941985
    CA Product Vulnerability Response Team
    
    
    CA, 1 CA Plaza, Islandia, NY 11749
    	
    Contact http://www.ca.com/us/contact/
    Legal Notice http://www.ca.com/us/legal/
    Privacy Policy http://www.ca.com/us/privacy/
    Copyright (c) 2008 CA. All rights reserved.
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    ====================================================================== 
    
                         Secunia Research 11/12/2008
    
         - CA ARCserve Backup RPC "handle_t" Argument Vulnerability -
    
    ====================================================================== 
    Table of Contents
    
    Affected Software....................................................1
    Severity.............................................................2
    Vendor's Description of Software.....................................3
    Description of Vulnerability.........................................4
    Solution.............................................................5
    Time Table...........................................................6
    Credits..............................................................7
    References...........................................................8
    About Secunia........................................................9
    Verification........................................................10
    
    ====================================================================== 
    1) Affected Software 
    
    * CA ARCserve Backup 11.5 SP4 build 4491.
    
    NOTE: Other versions may also be affected.
    
    ====================================================================== 
    2) Severity 
    
    Rating: Moderately critical
    Impact: System access
    Where:  Local network
    
    ====================================================================== 
    3) Vendor's Description of Software 
    
    "It is a reliable and comprehensive data protection solution trusted
    by hundreds of thousands users. It offers market-leading features,
    functionality and performance to provide data protection that
    minimizes costs, streamlines administrative tasks and operations and
    is part of a comprehensive integrated recovery solution."
    
    Product Link:
    http://www.ca.com/us/data-loss-prevention.aspx
    
    ====================================================================== 
    4) Description of Vulnerability
    
    Secunia Research has discovered a vulnerability in BrightStor ARCserve
    Backup, which can be exploited by malicious people to compromise a
    vulnerable system.
    
    The vulnerability is caused due to insufficient validation of 
    "handle_t" arguments passed to RPC endpoints. Passing object pointers
    to procedures that expect different types can result in arbitrary code
    execution.
    
    ====================================================================== 
    5) Solution 
    
    Apply patches released by the vendor.
    
    ====================================================================== 
    6) Time Table 
    
    24/10/2007 - Vendor notified.
    24/10/2007 - Vendor response.
    21/11/2007 - Status update requested.
    21/11/2007 - Vendor responds that development is working on patches.
    07/04/2008 - Status update requested.
    08/04/2008 - Vendor notifies expected release in May 2008.
    21/05/2008 - Vendor notifies expected release in October 2008.
    10/11/2008 - Vendor informed that October release did not fix the
                 reported vulnerability in version 11.5.
    10/11/2008 - Vendor requests additional information.
    10/11/2008 - Additional information provided to the vendor.
    11/11/2008 - Vendor asks for further clarification.
    11/11/2008 - Additional information about testing provided to vendor.
    14/11/2008 - Vendor informed that fixes for version 12 correctly 
                 addressed the reported vulnerability.
    18/11/2008 - Vendor provides beta patch for version 11.5.
    20/11/2008 - Vendor informed that beta patch fixes the vulnerability.
    11/12/2008 - Public disclosure.
    
    ====================================================================== 
    7) Credits 
    
    Discovered by Dyon Balding, Secunia Research.
    
    ====================================================================== 
    8) References
    
    The Common Vulnerabilities and Exposures (CVE) project has assigned 
    CVE-2008-5415 for the vulnerability.
    
    ====================================================================== 
    9) About Secunia
    
    Secunia offers vulnerability management solutions to corporate
    customers with verified and reliable vulnerability intelligence
    relevant to their specific system configuration:
    
    http://secunia.com/advisories/business_solutions/
    
    Secunia also provides a publicly accessible and comprehensive advisory
    database as a service to the security community and private 
    individuals, who are interested in or concerned about IT-security.
    
    http://secunia.com/advisories/
    
    Secunia believes that it is important to support the community and to
    do active vulnerability research in order to aid improving the 
    security and reliability of software in general:
    
    http://secunia.com/secunia_research/
    
    Secunia regularly hires new skilled team members. Check the URL below
    to see currently vacant positions:
    
    http://secunia.com/corporate/jobs/
    
    Secunia offers a FREE mailing list called Secunia Security Advisories:
    
    http://secunia.com/advisories/mailing_lists/
    
    ====================================================================== 
    10) Verification 
    
    Please verify this advisory by visiting the Secunia website:
    http://secunia.com/secunia_research/2007-82/
    
    Complete list of vulnerability reports published by Secunia Research:
    http://secunia.com/secunia_research/
    
    ======================================================================
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    Title: CA20090107-01: CA Service Metric Analysis and CA Service 
    Level Management smmsnmpd Arbitrary Command Execution 
    Vulnerability
    
    
    CA Advisory Reference: CA20090107-01
    
    
    CA Advisory Date: 2009-01-07
    
    
    Reported By:
    Michel Arboi of Tenable Network Security
    
    
    Impact: A remote attacker can execute arbitrary commands.
    
    
    Summary: CA Service Metric Analysis and CA Service Level 
    Management contain a vulnerability that can allow a remote 
    attacker to execute arbitrary commands. CA has issued patches to 
    address the vulnerability.  The vulnerability, CVE-2009-0043, 
    is due to insufficient access restrictions associated with the 
    smmsnmpd service. A remote attacker can exploit this vulnerability 
    to execute arbitrary commands in the context of the service.
    
    
    Mitigating Factors: None
    
    
    Severity: CA has given this vulnerability a High risk rating.
    
    
    Affected Products:
    CA Service Level Management 3.5
    CA Service Metric Analysis r11.0
    CA Service Metric Analysis r11.1
    CA Service Metric Analysis r11.1 SP1
    
    
    Affected Platforms:
    Windows
    
    
    Status and Recommendation:
    CA has issued the following patches to address the 
    vulnerabilities. 
    
    CA Service Level Management 3.5:
    RO04649
    
    CA Service Metric Analysis r11.0:
    RO04653
    
    CA Service Metric Analysis r11.1,
    CA Service Metric Analysis r11.1 SP1:
    RO04667
    
    
    How to determine if you are affected:
    
    1.  Run the ApplyPTF utility (preferably the latest one from CA) 
        on the machine where SMA/SLM is installed.
    2.  Select the option "List PTFs applied on local or remote 
        nodes." and click Next.
    3.  Enter the hostname of the machine on which SMA/SLM is 
        installed in the "List PTF(s) on Node:" input box and make 
        sure that "List Node Type" is set to "NT".  In the input box
        "Write Output to File", you may set the complete path to a 
        text file where the output may be written, for example, 
        "C:\ptflist.txt". Click Next. 
    4.  Select "UNISLM" in the Product section and click Next.
    5.  The list of fixes that have been applied on SMA will be 
        provided in the output section and also written to the file 
        specified in Step 3.
    6.  Manually verify if the output contains the following line: 
        a.  If the product version is SMA 11.1x, the line should be 
            "PTF Wizard installed T5LX006".
        b.  If the product version is SLM 3.5, the line should be "PTF 
            Wizard installed T5LX007".
        c.  If the product version is SMA 11.0, the line should be 
            "PTF Wizard installed T5LX008".
    7.  If the line is not present, then the product is vulnerable; 
        else, it has been patched.
    
    
    Workaround: None
    
    
    References (URLs may wrap):
    CA Support:
    http://support.ca.com/
    CA20090107-01: Security Notice for CA Service Metric Analysis and 
    CA Service Level Management
    https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=1961
    48
    Solution Document Reference APARs:
    RO04649, RO04653, RO04667
    CA Security Response Blog posting:
    CA20090107-01: CA Service Metric Analysis and CA Service Level 
    Management smmsnmpd Arbitrary Command Execution Vulnerability
    community.ca.com/blogs/casecurityresponseblog/archive/2009/01/07.aspx
    Reported By: 
    Michel Arboi of Tenable Network Security
    http://www.tenablesecurity.com/
    CVE References:
    CVE-2009-0043 - SMA smmsnmpd command execution
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0043
    OSVDB References: Pending
    http://osvdb.org/
    
    
    Changelog for this advisory:
    v1.0 - Initial Release
    
    
    Customers who require additional information should contact CA
    Technical Support at http://support.ca.com.
    
    For technical questions or comments related to this advisory, 
    please send email to vuln AT ca DOT com.
    
    If you discover a vulnerability in CA products, please report your 
    findings to the CA Product Vulnerability Response Team.
    https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=1777
    82
    
    
    Regards,
    Ken Williams, Director ; 0xE2941985
    CA Product Vulnerability Response Team
    
    
    CA, 1 CA Plaza, Islandia, NY 11749
    	
    Contact http://www.ca.com/us/contact/
    Legal Notice http://www.ca.com/us/legal/
    Privacy Policy http://www.ca.com/us/privacy/
    Copyright (c) 2009 CA. All rights reserved.
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra