CVE-2009-3587: Critical severity computer associates internet security suite vulnerability

Published Oct 13, 2009
·
Updated

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.

Affected Software

54 affected components
CA Internet Security Suite Plus 2009
CA Gateway Security=r8.1
CA Common Services=3.1
CA eTrust Secure Content Manager=8.0
CA Etrust Anti-virus Sdk
CA Anti-Virus for the Enterprise=r8.1
CA Arcserve For Windows Server Component
CA eTrust Intrusion Detection=2.0-sp1
CA Threat Manager=8.1
CA Protection Suites=r3
CA eTrust EZ Antivirus=r7.1
CA Internet Security Suite 2008
CA Anti-Virus=2009
CA eTrust Intrusion Detection=3.0-sp1
CA Anti-virus Plus=2009
CA Protection Suites=r3.1
CA Anti-virus Gateway=7.1
CA Threat Manager=r8
CA Etrust Anti-virus Gateway=7.1
CA Arcserve For Windows Client Agent
CA ARCserve Backup=r11.5
CA Threat Manager Total Defense
CA Internet Security Suite Plus 2008
CA Protection Suites=r2
Broadcom Anti-virus=2008
Broadcom Anti-virus=2007-8
Broadcom Anti-virus Sdk
Broadcom Anti-virus For The Enterprise=r8
Broadcom Anti-virus For The Enterprise=7.1
Broadcom Common Services=11
Broadcom Common Services=11.1
Broadcom Etrust Antivirus=7.1
Broadcom Etrust Antivirus=8.1
Broadcom Etrust Antivirus=8
Broadcom Etrust Integrated Threat Management=8.1
Broadcom Etrust Intrusion Detection=3.0
Broadcom Etrust Secure Content Manager=1.1
Broadcom Internet Security Suite
Broadcom Internet Security Suite=3.0
Broadcom Network And Systems Management=r11
Broadcom Network And Systems Management=r3.0
Broadcom Network And Systems Management=r11.1
Broadcom Network And Systems Management=r3.1
Broadcom Secure Content Manager=1.1
Broadcom Secure Content Manager=8.0
Broadcom Unicenter Network And Systems Management=3.0
Broadcom Unicenter Network And Systems Management=3.1
Broadcom Unicenter Network And Systems Management=11
Broadcom Unicenter Network And Systems Management=11.1
All of the following
Any of the following
CA ARCserve Backup=r11.1
CA ARCserve Backup=r11.5
Linux Linux kernel
CA ARCserve Backup=r11.1
Linux Linux

Event History

Oct 13, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2009-3587?

CVE-2009-3587 has a high severity due to its impact on multiple CA Anti-Virus products.

2

How do I fix CVE-2009-3587?

To fix CVE-2009-3587, update your CA Anti-Virus software to the latest version as specified by Broadcom.

3

Which products are affected by CVE-2009-3587?

CVE-2009-3587 affects various versions of CA Anti-Virus for the Enterprise, eTrust Antivirus, and CA Internet Security Suite among others.

4

What type of vulnerability is CVE-2009-3587?

CVE-2009-3587 is classified as an unspecified vulnerability within the arclib component of the Anti-Virus engine.

5

Is there a workaround for CVE-2009-3587?

Currently, the best mitigation for CVE-2009-3587 is to apply the available patches or upgrade the affected software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203