CVE-2009-3588

UnknownEPSS 2.39%

Last modified

CVE-2009-3588 is a vulnerability of currently unknown severity. Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.. EPSS estimates a 2.39% chance of exploitation in the next 30 days.

Description

Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.

Metrics

EPSS Probability
2.39%

81.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
BroadcomAnti-Virus20078
BroadcomAnti-Virus2008
BroadcomAnti-Virus For The Enterprise7.1
BroadcomAnti-Virus For The Enterpriser8
BroadcomAnti-Virus SdkAll versions
BroadcomCommon Services11
BroadcomCommon Services11.1
BroadcomEtrust Antivirus7.1
BroadcomEtrust Antivirus8
BroadcomEtrust Antivirus8.1
BroadcomEtrust Integrated Threat Management8.1
BroadcomEtrust Intrusion Detection3.0
BroadcomEtrust Secure Content Manager1.1
BroadcomInternet Security SuiteAll versions
BroadcomInternet Security Suite3.0
BroadcomNetwork And Systems Managementr3.0
BroadcomNetwork And Systems Managementr3.1
BroadcomNetwork And Systems Managementr11
BroadcomNetwork And Systems Managementr11.1
BroadcomSecure Content Manager1.1
BroadcomSecure Content Manager8.0
BroadcomUnicenter Network And Systems Management3.0
BroadcomUnicenter Network And Systems Management3.1
BroadcomUnicenter Network And Systems Management11
BroadcomUnicenter Network And Systems Management11.1
CaAnti-Virus2009
CaAnti-Virus For The Enterpriser8.1
CaAnti-Virus Gateway7.1
CaAnti-Virus Plus2009
CaArcserve For Windows Client AgentAll versions
CaArcserve For Windows Server ComponentAll versions
CaCommon Services3.1
CaEtrust Anti-Virus Gateway7.1
CaEtrust Anti-Virus SdkAll versions
CaEtrust Ez Antivirusr7.1
CaEtrust Intrusion Detection2.0Sp1
CaEtrust Intrusion Detection3.0Sp1
CaEtrust Secure Content Manager8.0
CaGateway Securityr8.1
CaInternet Security Suite 2008All versions
CaInternet Security Suite Plus 2008All versions
CaInternet Security Suite Plus 2009All versions
CaProtection Suitesr2
CaProtection Suitesr3
CaProtection Suitesr3.1
CaThreat Manager8.1
CaThreat Managerr8
CaThreat Manager Total DefenseAll versions
BroadcomArcserve Backupr12.0Sp1
CaArcserve Backupr11.5

Showing 50 of 51 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-3588?
Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.
How severe is CVE-2009-3588?
Severity scoring for CVE-2009-3588 is pending analysis. The EPSS model estimates a 2.39% probability of exploitation in the next 30 days.
How do I fix CVE-2009-3588?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-3588?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST