HIGH · 9.3

CVE-2009-3587

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust E...

Vulnerability Description

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
BroadcomAnti-Virus2007
BroadcomAnti-Virus For The Enterprise7.1
BroadcomAnti-Virus SdkAll versions
BroadcomCommon Services11
BroadcomEtrust Antivirus7.1
BroadcomEtrust Integrated Threat Management8.1
BroadcomEtrust Intrusion Detection3.0
BroadcomEtrust Secure Content Manager1.1
BroadcomInternet Security SuiteAll versions
BroadcomNetwork And Systems Managementr3.0
BroadcomSecure Content Manager1.1
BroadcomUnicenter Network And Systems Management3.0
CaAnti-Virus2009
CaAnti-Virus For The Enterpriser8.1
CaAnti-Virus Gateway7.1
CaAnti-Virus Plus2009
CaArcserve Backupr11.5
CaArcserve For Windows Client AgentAll versions
CaArcserve For Windows Server ComponentAll versions
CaCommon Services3.1

References

FAQ

What is CVE-2009-3587?

CVE-2009-3587 is a vulnerability with a CVSS score of 9.3 (HIGH). Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust E...

How severe is CVE-2009-3587?

CVE-2009-3587 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-3587?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Anti-Virus, Broadcom Anti-Virus For The Enterprise, Broadcom Anti-Virus Sdk, Broadcom Common Services, Broadcom Etrust Antivirus.