CVE-2009-3588
published 2009-10-13CVE-2009-3588: Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.39%
81.9th percentile
Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| broadcom | anti-virus | — | — |
| broadcom | anti-virus | — | — |
| broadcom | anti-virus_for_the_enterprise | — | — |
| broadcom | anti-virus_for_the_enterprise | — | — |
| broadcom | arcserve_backup | — | — |
| broadcom | common_services | — | — |
| broadcom | common_services | — | — |
| broadcom | etrust_antivirus | — | — |
| broadcom | etrust_antivirus | — | — |
| broadcom | etrust_antivirus | — | — |
| broadcom | etrust_integrated_threat_management | — | — |
| broadcom | etrust_intrusion_detection | — | — |
| broadcom | etrust_secure_content_manager | — | — |
| broadcom | internet_security_suite | — | — |
| broadcom | network_and_systems_management | — | — |
| broadcom | network_and_systems_management | — | — |
| broadcom | network_and_systems_management | — | — |
| broadcom | network_and_systems_management | — | — |
| broadcom | secure_content_manager | — | — |
| broadcom | secure_content_manager | — | — |
| broadcom | unicenter_network_and_systems_management | — | — |
| broadcom | unicenter_network_and_systems_management | — | — |
| broadcom | unicenter_network_and_systems_management | — | — |
| broadcom | unicenter_network_and_systems_management | — | — |
| ca | anti-virus | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q64c-hf5x-986j: Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7
ghsa_unreviewed·2022-05-02·CVSS 4.3
CVE-2009-3587 [MEDIUM] GHSA-q64c-hf5x-986j: Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7
Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588.
GHSA
GHSA-xhpm-r2g2-c7vg: Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2009-3588 [CRITICAL] GHSA-xhpm-r2g2-c7vg: Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7
Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/36976http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=218878http://www.securityfocus.com/archive/1/507068/100/0/threadedhttp://www.securityfocus.com/bid/36653http://www.securitytracker.com/id?1022999http://www.vupen.com/english/advisories/2009/2852https://exchange.xforce.ibmcloud.com/vulnerabilities/53698http://secunia.com/advisories/36976http://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=218878http://www.securityfocus.com/archive/1/507068/100/0/threadedhttp://www.securityfocus.com/bid/36653http://www.securitytracker.com/id?1022999http://www.vupen.com/english/advisories/2009/2852https://exchange.xforce.ibmcloud.com/vulnerabilities/53698
2009-10-13
Published