CVE-2008-3175
Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a buffer overflow.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 14.40% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- broadcom/brightstor arcserve backup · broadcom/desktop management suite · ca/arcserve backup for laptops and desktops · ca/brightstor arcserve backup · ca/protection suites
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063594.html
- http://secunia.com/advisories/31319Vendor Advisory
- http://www.securityfocus.com/archive/1/495020/100/0/threaded
- http://www.securityfocus.com/bid/30472Patch
- http://www.securitytracker.com/id?1020590
- http://www.vupen.com/english/advisories/2008/2286Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44137
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181721Patch, Vendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063594.html
- http://secunia.com/advisories/31319Vendor Advisory
- http://www.securityfocus.com/archive/1/495020/100/0/threaded
- http://www.securityfocus.com/bid/30472Patch
- http://www.securitytracker.com/id?1020590
- http://www.vupen.com/english/advisories/2008/2286Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44137
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181721Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.