CA eliminates three week old vulnerability in BrightStor ARCserve
Computer Associates has finally released an update for the vulnerability announced three weeks ago in BrightStor ARCserve Backup. An exploit has been circulating since the problem became apparent. The bug was discovered in an RPC service that processes specific strings, allowing code to be injected and executed. According to the error report from CA, a further vulnerability, which existed there as well, has also been eliminated by the update.
The following were affected: BrightStor ARCserve Backup r11.5, r11.1, r11 for Windows, BrightStor Enterprise Backup r10.5, v9.01, Server Protection Suite r2, CA Business Protection Suite r2 and Business Protection Suite for Microsoft Small Business Server Standard Edition r2 and Premium Edition r2.
- BrightStor ARCserve Backup Media Server Security Notice, error report from CA