CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities
11 May 2009
Summary
CA ARCserve Backup on Solaris, Tru64, HP-UX, and AIX contains multiple vulnerabilities in the Apache HTTP Server version as shipped with ARCserve Backup. A remote attacker can exploit a buffer overflow to gain apache privileges, or cause a denial of service. CA has issued updates that contain version 2.0.63 of the Apache HTTP Server to address the vulnerabilities.
Vulnerable Systems:
* CA ARCserve Backup r11.5 Solaris
* CA ARCserve Backup r11.5 Tru64
* CA ARCserve Backup r11.5 HP-UX
* CA ARCserve Backup r11.5 AIX
Patch Availability:
* CA ARCserve Backup r11.5 Solaris: RO06786
* CA ARCserve Backup r11.5 Tru64: RO06788
* CA ARCserve Backup r11.5 HP-UX: RO06789
* CA ARCserve Backup r11.5 AIX: RO06791
Workaround:
As a workaround solution, disable the Apache HTTP Server with the "stopgui" command. To re-enable the server, run "startgui".
Stopping the Apache HTTP Server will prevent the ARCserve user from performing GUI operations. Most of the operations provided by the GUI can be accomplished via the command line.
Alternatively, restrict remote network access to reduce exposure.