CVE-2009-1761: Input Validation
Published Jun 16, 2009
·Updated
The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.
Affected Software
2 affected components
CA ARCserve Backup=r12.0
CA ARCserve Backup=r12.0-sp1
Remediation
Event History
Jun 16, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1761?
CVE-2009-1761 is a high severity vulnerability that leads to a denial of service.
2
How do I fix CVE-2009-1761?
To fix CVE-2009-1761, update your CA ARCserve Backup software to the latest version or apply any available patches.
3
What affects CVE-2009-1761?
CVE-2009-1761 affects CA ARCserve Backup r12.0 and r12.0 SP1 for Windows.
4
What are the types of messages that exploit CVE-2009-1761?
CVE-2009-1761 can be exploited through an invalid 0x13 message or a 0x3B message with invalid stub data.
5
Can CVE-2009-1761 be exploited remotely?
Yes, CVE-2009-1761 can be exploited remotely by attackers.