First published: Tue Oct 13 2009(Updated: )
Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Internet Security Suite | ||
Symantec Gateway Security | =r8.1 | |
CA Common Services | =3.1 | |
Broadcom Secure Content Manager | =8.0 | |
Broadcom eTrust Antivirus SDK | ||
Broadcom Anti-Virus for the Enterprise | =r8.1 | |
Broadcom CA Arcserve for Windows Server Component | ||
Broadcom eTrust Intrusion Detection | =2.0-sp1 | |
Broadcom CA Threat Manager | =8.1 | |
CA Protection Suites | =r3 | |
Broadcom eTrust EZ Antivirus | =r7.1 | |
Broadcom Internet Security Suite | ||
CA Anti-Virus | =2009 | |
Broadcom eTrust Intrusion Detection | =3.0-sp1 | |
CA Anti-Virus Plus | =2009 | |
CA Protection Suites | =r3.1 | |
CA eTrust Anti-Virus Gateway | =7.1 | |
Broadcom CA Threat Manager | =r8 | |
Broadcom eTrust Antivirus Gateway | =7.1 | |
CA BrightStor ARCserve Client | ||
CA Threat Manager | ||
Broadcom Internet Security Suite | ||
CA Protection Suites | =r2 | |
broadcom Anti-Virus | =2008 | |
broadcom Anti-Virus | =2007-8 | |
Broadcom Antivirus SDK | ||
Broadcom Anti-Virus for the Enterprise | =r8 | |
Broadcom Anti-Virus for the Enterprise | =7.1 | |
broadcom common services | =11 | |
broadcom common services | =11.1 | |
Broadcom eTrust Antivirus | =7.1 | |
Broadcom eTrust Antivirus | =8.1 | |
Broadcom eTrust Antivirus | =8 | |
Broadcom CA Threat Manager | =8.1 | |
Broadcom eTrust Intrusion Detection | =3.0 | |
Broadcom Secure Content Manager | =1.1 | |
Broadcom Internet Security Suite | ||
Broadcom Internet Security Suite | =3.0 | |
CA Network and Systems Management | =r11 | |
CA Network and Systems Management | =r3.0 | |
CA Network and Systems Management | =r11.1 | |
CA Network and Systems Management | =r3.1 | |
Broadcom Secure Content Manager | =1.1 | |
Broadcom Secure Content Manager | =8.0 | |
CA Network and Systems Management | =3.0 | |
CA Network and Systems Management | =3.1 | |
CA Network and Systems Management | =11 | |
CA Network and Systems Management | =11.1 | |
Broadcom BrightStor ARCserve Backup | =r12.0-sp1 | |
Broadcom BrightStor ARCserve Backup | =r12.0-sp2 | |
CA ARCserve Backup for Laptops and Desktops | =r11.5 | |
Microsoft Windows | ||
CA ARCserve Backup for Laptops and Desktops | =r11.1 | |
Linux | ||
All of | ||
Any of | ||
Broadcom BrightStor ARCserve Backup | =r12.0-sp1 | |
Broadcom BrightStor ARCserve Backup | =r12.0-sp2 | |
CA ARCserve Backup for Laptops and Desktops | =r11.5 | |
Microsoft Windows | ||
All of | ||
Any of | ||
CA ARCserve Backup for Laptops and Desktops | =r11.1 | |
CA ARCserve Backup for Laptops and Desktops | =r11.5 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-3588 is classified as critical due to the potential for unauthorized access and system compromise.
To fix CVE-2009-3588, users should update their CA Anti-Virus and related products to the latest patched versions provided by Broadcom.
CVE-2009-3588 affects multiple CA products including CA Anti-Virus for the Enterprise, eTrust Antivirus, and various versions of Internet Security Suite.
Exploitation of CVE-2009-3588 could allow an attacker to execute arbitrary code, potentially leading to full system compromise.
Temporary workarounds for CVE-2009-3588 may include disabling the vulnerable arclib component until a patch can be applied.