Short Name |
APP:CA:ARCSRV:TAPE-ENGINE-DOS |
|---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
APP |
Keywords |
CA ARCserve Backup Tape Engine DoS |
Release Date |
2010/10/14 |
Update Number |
1792 |
Supported Platforms |
idp-4.1.110110609+, isg-3.5.139308+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects attempts to exploit a known vulnerability in CA BrightStor ARCserve Backup Tape Engine service. It is due to insufficient input validation in the ClientCreateJobHandle library function. A remote unauthenticated attacker can exploit this by sending a crafted message to the target server. A successful attack can cause a denial-of-service condition for the TapeEng and MediaSrv services. Upon processing the malicious RPC message, the TapeEng.exe process terminates, followed by Mediasvr.exe, and causes a denial-of-service condition. As TapeEng is hosted as a Windows services it can be configured on some operating systems, like Windows Server 2003, to automatically restart upon abnormal termination.
Computer Associates ARCserve Backup is prone to multiple remote vulnerabilities. Successful exploits allow remote attackers to cause denial-of-service conditions or to execute arbitrary commands in the context of the affected application. This may result in a complete compromise of affected computers. The following applications are affected: CA BrightStor ARCserve Backup r11.1, r11.5, r12.0 for Windows CA Server Protection Suite r2 CA Business Protection Suite r2 CA Business Protection Suite for Microsoft Small Business Server Standard Edition r2 CA Business Protection Suite for Microsoft Small Business Server Premium Edition r2