Vulnerabilities > CVE-2005-1018 - Remote Buffer Overflow vulnerability in CA Brightstor Arcserve Backup 11.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ca
nessus
exploit available
metasploit

Summary

Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticated users to cause a denial of service or execute arbitrary code via an agent request to TCP port 6050 with a large argument before the option field.

Vulnerable Configurations

Part Description Count
Application
Ca
1

Exploit-Db

descriptionCA BrightStor Universal Agent Overflow. CVE-2005-1018. Remote exploit for windows platform
idEDB-ID:16405
last seen2016-02-01
modified2010-06-22
published2010-06-22
reportermetasploit
sourcehttps://www.exploit-db.com/download/16405/
titleCA BrightStor Universal Agent Overflow

Metasploit

descriptionThis module exploits a convoluted heap overflow in the CA BrightStor Universal Agent service. Triple userland exception results in heap growth and execution of dereferenced function pointer at a specified address.
idMSF:EXPLOIT/WINDOWS/BRIGHTSTOR/UNIVERSAL_AGENT
last seen2020-01-14
modified2017-07-24
published2005-12-05
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/brightstor/universal_agent.rb
titleCA BrightStor Universal Agent Overflow

Nessus

NASL familyWindows
NASL idARCSERVE_UNIVERSALAGENT_OVERFLOW.NASL
descriptionThis host is running BrightStor ARCServe UniversalAgent. The remote version of this software is affected by a buffer overflow vulnerability. An attacker, by sending a specially crafted packet, may be able to execute code on the remote host.
last seen2020-06-01
modified2020-06-02
plugin id18041
published2005-04-13
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/18041
titleCA BrightStor ARCserve Backup Universal Agent Remote Overflow (QO66526)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83156/universal_agent.rb.txt
idPACKETSTORM:83156
last seen2016-12-05
published2009-11-26
reporterH D Moore
sourcehttps://packetstormsecurity.com/files/83156/CA-BrightStor-Universal-Agent-Overflow.html
titleCA BrightStor Universal Agent Overflow

Saint

bid13102
descriptionBrightStor ARCserve Universal Agent buffer overflow
osvdb15471
titlebrightstor_arcserve_universal_agent
typeremote