First published: Tue Jan 16 2007(Updated: )
Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Protection Suites r2 allows remote attackers to execute arbitrary code via crafted SUNRPC packets, aka the "Mediasvr.exe Overflow," a different vulnerability than CVE-2006-5172.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CA Protection Suites | =r2 | |
Broadcom ARCserve Backup | <=11.5 | |
Broadcom ARCserve Backup | =9.01 | |
Broadcom BrightStor Enterprise Backup | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5171 is considered critical due to its potential for remote code execution.
To fix CVE-2006-5171, update the affected software to a version that has patched the vulnerability.
CVE-2006-5171 affects CA Protection Suites r2, Broadcom BrightStor ARCServe Backup versions 9.01 to 11.5, and Enterprise Backup 10.5.
Yes, CVE-2006-5171 can be exploited remotely through crafted SUNRPC packets.
Exploiting CVE-2006-5171 could allow an attacker to execute arbitrary code on the affected system.