BrightStor ARCserve Backup LGServer rxsUseLicenseIni buffer overflow
Added: 01/11/2008CVE: CVE-2007-3216
BID: 24348
OSVDB: 35329
Background
BrightStor ARCserve Backup for Laptops and Desktops is an automated backup solution optimized for low-bandwidth, intermittent network connections.Problem
A buffer overflow vulnerability in the rxsUseLicenseIni function allows remote attackers to execute arbitrary commands by sending a specially crafted request to the LGServer on port 1900.Resolution
Apply one of the updates referenced in the Security Notice.References
http://www.frsirt.com/english/advisories/2007/2121Limitations
Exploit works on BrightStor ARCserve Backup for Laptops and Desktops 11.1 SP1.Platforms
Windows 2000Windows Server 2003
Back to exploit index