CVE-2009-3587
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD
Description
Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.
Affected (50)
Products: Broadcom: Anti Virus, Anti Virus For The Enterprise, Anti Virus Sdk, Common Services, Etrust Antivirus, Etrust Integrated Threat Management, Etrust Intrusion Detection, Etrust Secure Content Manager, Internet Security Suite, Network And Systems Management, Secure Content Manager, Unicenter Network And Systems Management · Ca: Anti Virus, Anti Virus For The Enterprise, Anti Virus Gateway, Anti Virus Plus, Arcserve For Windows Client Agent, Arcserve For Windows Server Component, Common Services, Etrust Anti Virus Gateway, Etrust Anti Virus Sdk, Etrust Ez Antivirus, Etrust Intrusion Detection, Etrust Secure Content Manager, Gateway Security, Internet Security Suite 2008, Internet Security Suite Plus 2008, Internet Security Suite Plus 2009, Protection Suites, Threat Manager, Threat Manager Total Defense, Arcserve Backup
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2007 8 | |
| Version 7.1 | |
| All versions | |
| Version 11.1 | |
| Version 7.1 | |
| Version 8.1 | |
| Version 3.0 | |
| Version 1.1 | |
| All versions | |
| Version r11.1 | |
| Version 1.1 | |
| Version 11.1 | |
| Version 2009 | |
| Version r8.1 | |
| Version 7.1 | |
| Version 2009 | |
| All versions | |
| All versions | |
| Version 3.1 | |
| Version 7.1 | |
| All versions | |
| Version r7.1 | |
| Version 2.0 sp1 | |
| Version 8.0 | |
| Version r8.1 | |
| All versions | |
| All versions | |
| All versions | |
| Version r2 | |
| Version 8.1 | |
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version r11.1 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
References (16)
Source: cve@mitre.org
Broken LinkPatchVendor Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.