CA plugs serious hole in backup software

A serious security flaw in Computer Associates backup products could put corporate systems at risk of cyberattack, security companies have warned.

The vulnerability lies in CA's BrightStor ARCserve Backup Agents and BrightStor Enterprise Backup Agents, according to an alert from the French Security Incident Response Team released on Wednesday. The software handles backups of critical systems, FrSirt said.

CA issued software patches to fix the problem on Tuesday.

With the flaw, an intruder could gain full control over the system that runs the backup software by sending an especially crafted request to the agent, said FrSirt, which rates the issue "critical." Code that exploits the flaws is available on the Internet, the French research organisation noted.

Data backup tools have become easy targets for attackers, the SANS Institute said in its most recent quarterly security update. Serious security vulnerabilities have been disclosed in products from CA and Veritas in recent months, SANS said.

The BrightStor problem is caused by a remote buffer overflow error in the CA software, according to an advisory from iDefense, which is credited with the discovery of the flaw. Users should apply the fixes or, as a work-around, restrict access to the backup agents from remote networks, iDefense said.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Get extensions going in Firefox, redux
    Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
  • Array How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • More blogs »

Tags

Back to top

Featured