HIGH · 9.3

CVE-2007-3825

Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterpri...

Vulnerability Description

Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certain data to unspecified RPC procedures.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
BroadcomAlert Notification ServerAll versions
BroadcomBrightstor Arcserve Backup9.01
BroadcomBrightstor Enterprise Backup10.5
CaAnti-Virus For The Enterprise8
CaBrightstor Arcserve Backup11
CaBrightstor Arcserve ClientAll versions
CaProtection Suitesr3
CaThreat Manager8

References

FAQ

What is CVE-2007-3825?

CVE-2007-3825 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterpri...

How severe is CVE-2007-3825?

CVE-2007-3825 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3825?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Alert Notification Server, Broadcom Brightstor Arcserve Backup, Broadcom Brightstor Enterprise Backup, Ca Anti-Virus For The Enterprise, Ca Brightstor Arcserve Backup.