VDB
CVE-2007-0169
CVE-2007-0169
PUBLISHED
CVSS 7.5 HIGH
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data for opnums (1) 0x2F and (2) 0x75 in the (a) Message Engine RPC service, or opnum (3) 0xCF in the Tape Engine service.
EPSS 77.82% · 99.0th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
77.82%
99.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| broadcom | business_protection_suite | 2.0 |
| n/a | n/a | n/a |
| broadcom | brightstor_enterprise_backup | 10.5 |
| broadcom | brightstor_arcserve_backup | 0, 9.01 |
Timeline
- Jan 11, 2007 CVE Published
- Apr 30, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 8, 2023 EPSS Score
- Jun 15, 2023 EPSS Score
References
- 20070111 ZDI-07-003: CA BrightStor ARCserve Backup Message Engine Buffer Overflow Vulnerability mailing-list
- http://supportconnectw.ca.com/public/storage/infodocs/babimpsec-notice.asp url
- brightstor-messageengine-rpc-bo(31443) vdb
- http://www.zerodayinitiative.com/advisories/ZDI-07-004.html url
- 1017506 vdb
- 22006 vdb
- 22005 vdb
- 20070111 [CAID 34955, 34956, 34957, 34958, 34959, 34817]: CA BrightStor ARCserve Backup Multiple Overflow Vulnerabilities mailing-list
- 20070111 ZDI-07-004: CA BrightStor ARCserve Backup Tape Engine Buffer Overflow Vulnerability mailing-list
- 20070111 Computer Associates BrightStor ARCserve Backup RPC Engine PFC Request Buffer Overflow Vulnerability third-party-advisory
- ADV-2007-0154 vdb
- 31327 vdb
- VU#151032 third-party-advisory
- VU#180336 third-party-advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-003.html url
- brightstor-tapeengine-rpc-bo(31433) vdb
- 23648 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-0169 advisory