.:[ packet storm ]:.
                             
security without boundaries
security without boundaries

 ///  File Name:CA-caloggerdxdr.txt
Description:
CA ARCserve Backup contains multiple vulnerabilities that can allow a remote attacker to cause a denial of service or execute arbitrary code. CA has issued patches to address the vulnerabilities. The first vulnerability, CVE-2008-2241, is due to insufficient path verification by the logging service, caloggerd. An attacker can append data to arbitrary files, which can lead to system compromise. The second vulnerability, CVE-2008-2242, is due to insufficient bounds checking by multiple xdr functions. An attacker can cause an overflow and execute arbitrary code.
Author:Ken Williams
Homepage:http://www3.ca.com/
File Size:5864
Related CVE(s):CVE-2008-2241, CVE-2008-2242
Last Modified:May 19 21:36:12 2008
MD5 Checksum:612eed8dc378f0b53f234e2a163e0464

 .:. Back