Multiple buffer overflows in xdr functions in the server in CA BrightStor ARCServe Backup 11.0, 11.1, and 11.5 allow remote attackers to execute arbitrary code, as demonstrated by a stack-based buffer overflow via a long parameter to the xdr_rwsstring function.
| Software | From | Fixed in |
|---|---|---|
| ca / brightstor_arcserve_backup | 11.0 | 11.0.x |
| broadcom / brightstor_arcserve_backup | 11.5 | 11.5.x |
| broadcom / brightstor_arcserve_backup | 11.1 | 11.1.x |