* ____________________________________________________________________________ * * ID: 3 * PRODUCT: AXWBAS * RELEASE: 11.1 * DESC: NT -UPDATE FOR ANTIVIRUS SECURITY VULNERABILITY * SYSTEMS AFFECTED: NT * SOLUTION TEXT: PRODUCT: BAB Windows Common RELEASE: 11.1 APAR #: QO60812 DATE: 18 OCT 2004 PROBLEM DESCRIPTION: NT -UPDATE FOR ANTIVIRUS SECURITY VULNERABILITY ---------------------------------------------------- This update addresses a potential security vulnerability when using ARCserve to scan .zip files for viruses. Without this update, it is possible that malicious files contained within .zip files could avoid being detected by ARCserve's antivirus scanning functionality. This security vulnerability affects multiple vendors. If you are not using ARCserve's antivirus scanning functionality (set in the Job Options view), please check with your AntiVirus vendor to address this vulnerability. For more information on how this affects CA E-Trust, and other CA brands, please go to: http://supportconnectw.ca.com/public/ca_common_doc s/arclib_vuln.asp PREREQS: None MPREREQS: None COREQS: None MCOREQS: None SUPERSEDED: None HYPER: NO DISTRIBUTION CODE: A (A=Available, I=Internal) PROBLEM RESOLUTION: Follow the instructions below: This fix requires BrightStor ARCserve Backup Release 11.1 to be installed. 1. Shutdown all BrightStor ARCserve Backup services. 2. Unzip the fix file as follows: CAZIPXP -U QO60812.CAZ 3. Rename Arclib.dll in X:\Program Files\CA\SharedComponents\ScanEngine to Arclib.dll.QO60812. 4. Copy Arclib.dll to X:\Program Files\CA\SharedComponents\ScanEngine . 5. Start all BrightStor ARCserve Backup services. PRODUCT(S) AFFECTED: BrightStor ARCserve Backup for Windows Release 11.1 DOWNLOAD INFORMATION: --------------------- NODE: ftp.ca.com PATH: /CAproducts/unicenter/AXWBAS/nt/GA/QO60812 FILES: QO60812.DFC QO60812.CAZ UPDATED ROUTINES: --------------- arclib.dll 224144 THU OCT 14 12:04:48 2004 * ____________________________________________________________________________ * * NT VERSION: 0 EFFECTIVE: 10/18/2004 ACTION: A *** NO ZAPS FOR THIS VERSION ***