Vulnerability CVE-2010-3984


Published: 2011-01-07   Modified: 2012-02-13

Description:
Buffer overflow in mng_core_com.dll in CA XOsoft Replication r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft High Availability r12.0 SP1 and r12.5 SP2 rollup, CA XOsoft Content Distribution r12.0 SP1 and r12.5 SP2 rollup, and CA ARCserve Replication and High Availability (RHA) r15.0 SP1 allows remote attackers to execute arbitrary code via a crafted create_session_bab operation in a SOAP request to xosoapapi.asmx.

See advisories in our WLB2 database:
Topic
Author
Date
High
CA XOsoft 12 Security Notice
Kotas, Kevin J
11.01.2011

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
CA -> Arcserve replication and high availability 
CA -> Xosoft content distribution 
CA -> Xosoft high availability 
CA -> Xosoft replication 

 References:
http://www.securityfocus.com/archive/1/515115/100/0/threaded
http://www.securityfocus.com/bid/45317
http://www.securitytracker.com/id?1024852
http://www.zerodayinitiative.com/advisories/ZDI-10-263/
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7bFEB41CE8-5023-46DF-B257-5299F492BF23%7d

Copyright 2024, cxsecurity.com

 

Back to Top