CVE-2008-3175
Last modified
CVE-2008-3175 is a vulnerability of currently unknown severity. Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a buffer overflow.. EPSS estimates a 14.40% chance of exploitation in the next 30 days.
Description
Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Brightstor Arcserve Backup | 11.1 |
| Broadcom | Brightstor Arcserve Backup | 11.5 |
| Broadcom | Desktop Management Suite | 11.1 |
| Broadcom | Desktop Management Suite | 11.2 |
| Ca | Arcserve Backup For Laptops And Desktops | 11.0 |
| Ca | Arcserve Backup For Laptops And Desktops | 11.1 |
| Ca | Arcserve Backup For Laptops And Desktops | 11.5 |
| Ca | Brightstor Arcserve Backup | 11.0 |
| Ca | Brightstor Arcserve Backup | 11.1 |
| Ca | Protection Suites | 2 |
| Ca | Protection Suites | 3.0 |
| Ca | Protection Suites | 3.1 |
References
- http://secunia.com/advisories/31319Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2286Vendor Advisory
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181721Patch, Vendor Advisory
- http://secunia.com/advisories/31319Vendor Advisory
- http://www.vupen.com/english/advisories/2008/2286Vendor Advisory
- https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=181721Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3175?
How severe is CVE-2008-3175?
How do I fix CVE-2008-3175?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3169Multiple heap-based buffer overflows in Empire Server before…
- CVE-2008-3170Apple Safari allows web sites to set cookies for country-spe…
- CVE-2008-3171Apple Safari sends Referer headers containing https URLs to …
- CVE-2008-3172Opera allows web sites to set cookies for country-specific t…
- CVE-2008-3173Microsoft Internet Explorer allows web sites to set cookies …
- CVE-2008-3174Unspecified vulnerability in the kmxfw.sys driver in CA Host…
- CVE-2008-3177Sophos virus detection engine 2.75 on Linux and Unix, as use…
- CVE-2008-3178Unrestricted file upload vulnerability in upload_pictures.ph…
- CVE-2008-3179Directory traversal vulnerability in website.php in Web 2 Bu…
- CVE-2008-3180Multiple cross-site scripting (XSS) vulnerabilities in uploa…
- CVE-2008-3181Unrestricted file upload vulnerability in upload.php in Cont…
- CVE-2008-3182Stack-based buffer overflow in DAP.exe in Download Accelerat…
Are you affected by CVE-2008-3175?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
