CVE-2007-3216: Buffer Overflow
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote attackers to execute arbitrary code via crafted arguments to the (1) rxsAddNewUser, (2) rxsSetUserInfo, (3) rxsRenameUser, (4) rxsSetMessageLogSettings, (5) rxsExportData, (6) rxsSetServerOptions, (7) rxsRenameFile, (8) rxsACIManageSend, (9) rxsExportUser, (10) rxsImportUser, (11) rxsMoveUserData, (12) rxsUseLicenseIni, (13) rxsLicGetSiteId, (14) rxsGetLogFileNames, (15) rxsGetBackupLog, (16) rxsBackupComplete, (17) rxsSetDataProtectionSecurityData, (18) rxsSetDefaultConfigName, (19) rxsGetMessageLogSettings, (20) rxsHWDiskGetTotal, (21) rxsHWDiskGetFree, (22) rxsGetSubDirs, (23) rxsGetServerDBPathName, (24) rxsSetServerOptions, (25) rxsDeleteFile, (26) rxsACIManageSend, (27) rxcReadBackupSetList, (28) rxcWriteConfigInfo, (29) rxcSetAssetManagement, (30) rxcWriteFileListForRestore, (31) rxcReadSaveSetProfile, (32) rxcInitSaveSetProfile, (33) rxcAddSaveSetNextAppList, (34) rxcAddSaveSetNextFilesPathList, (35) rxcAddNextBackupSetIncWildCard, (36) rxcGetRevisions, (37) rxrAddMovedUser, (38) rxrSetClientVersion, or (39) rxsSetDataGrowthScheduleAndFilter commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3216?
CVE-2007-3216 has been classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2007-3216?
To fix CVE-2007-3216, update your CA BrightStor ARCserve Backup for Laptops and Desktops to the latest version released by the vendor.
Who is affected by CVE-2007-3216?
CVE-2007-3216 affects users of CA BrightStor ARCserve Backup for Laptops and Desktops version 11.1.
What type of vulnerability is CVE-2007-3216?
CVE-2007-3216 is a buffer overflow vulnerability that can allow attackers to execute arbitrary code.
Can CVE-2007-3216 be exploited remotely?
Yes, CVE-2007-3216 can be exploited remotely by attackers sending crafted arguments to the affected application.