CA Community






This Blog

December 2010 - Posts

CA20101231-01: Security Notice for CA ARCserve D2D

Published: December 31 2010, 05:21 PM | no comments
by Ken Williams

Today, we published a security notice to address a vulnerability in CA ARCserve D2D r15.  The security notice includes an informational solution for a high risk vulnerability that was publicly disclosed on 2010-12-30 by rgod.  Although the informational solution fully mitigates the vulnerability, we do still plan to release a patch soon as a more automated and permanent solution.  The individual who discovered and disclosed the vulnerability, rgod, has posted exploit code with his security notice.  CA was not contacted before the public disclosure.  We have not received any reports of active exploitation, but we do expect to see vulnerability scanning and exploitation activity.

The security notice for this vulnerability is published on the CA Support web site:

CA20101231-01: Security Notice for CA ARCserve D2D
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID={26223DAB-1FA0-4EF9-864E-6CE3278FE503

Thanks and regards,
Ken Williams, Director
ca technologies Product Vulnerability Response Team
ca technologies Business Unit Operations
wilja22@ca.com

The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA.
 

Share this post:  

 

By: Ken Williams
Ken Williams is a Director with the CA Vulnerability Research Team. As a veteran vulnerability researcher, Ken has worked as the Director of the CA Vulnerability Research Team and eVM Research Team, Director of Vulnerability Research at eSecurityOnline, Manager of the Vulnerability Research Team at Ernst...
Read More..

CA20101209-01: Security Notice for CA XOsoft

Published: December 09 2010, 02:23 PM | no comments
by Kevin Kotas

Today, I published a new security notice for XOsoft products. The notice concerns a High risk vulnerability that was privately reported to CA. Patches are now available. We are not aware of any reports of this vulnerability being actively exploited in the wild. See the notice below for additional details.

CA20101209-01: Security Notice for CA XOsoft
https://support.ca.com/irj/portal/anonymous/phpsupcontent?contentID=%7bFEB41CE8-5023-46DF-B257-5299F492BF23%7d

Kevin Kotas
CA Technologies Product Vulnerability Response Team

The opinions and statements on this site are my own and do not necessarily reflect the opinions or policies of CA.

Share this post:  

 

By: Kevin Kotas
Kevin Kotas is an Engineering Services Architect with the CA Product Vulnerability Response Team. He has over thirteen years of vulnerability management experience and discovered several vulnerabilities in products from multiple major software providers. Kevin holds a B.S. degree in Computer Science...
Read More..

More Posts