CVE-2006-6917
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll 11.5.3884.0, or (2) opnum 37, which is not properly handled in TAPEENG.dll 11.5.3884.0.
Date published : 2007-01-11
http://www.securityfocus.com/archive/1/453930/30/390/threaded
http://www.securityfocus.com/archive/1/453933/30/420/threaded
