First published: Sun Dec 31 2006(Updated: )
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is not properly handled in TAPEENG.dll 11.5.3884.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom ARCserve Backup | =11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6917 is categorized as a critical vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2006-6917, it's recommended to upgrade to CA BrightStor ARCserve Backup R11.5 Server Service Pack 2 or later.
CVE-2006-6917 specifically affects the Tape Engine component (tapeeng.exe) in CA BrightStor ARCserve Backup Server 11.5.
Attackers can exploit CVE-2006-6917 to execute arbitrary code remotely on vulnerable systems.
Users of CA BrightStor ARCserve Backup Server version 11.5 without the latest security updates are impacted by CVE-2006-6917.