CVE-2007-5331

CA BrightStor ARCServe Backup 9.01-R11.5 - Remote Code Execution via Malformed ONRPC Request

Title source: llm
STIX 2.1

Description

Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.

References (10)

Core 10
Core References
Various Sources third-party-advisory x_refsource_eeye
http://research.eeye.com/html/advisories/published/AD20071011.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27192
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24680
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/482114/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/482121/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37071
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018805
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41371
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3470

Scores

EPSS 0.1813
EPSS Percentile 95.3%

Details

CWE
CWE-94
Status published
Products (8)
broadcom/brightstor_arcserve_backup 9.01
broadcom/brightstor_arcserve_backup 11.1
broadcom/brightstor_arcserve_backup 11.5
broadcom/brightstor_enterprise_backup 10.5
broadcom/business_protection_suite 2.0
broadcom/server_protection_suite 2
ca/brightstor_arcserve_backup 11
ca/business_protection_suite 2.0 (2 CPE variants)
Published Oct 13, 2007
Tracked Since Feb 18, 2026