Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2009-3588


Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587.


Security Impact Summary

CVE-2009-3588 is a security vulnerability that . Impacting 35 products from broadcom, from broadcom, from broadcom and 32 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Originally identified in 2009, this vulnerability predates many modern security frameworks and practices. The vulnerability landscape of that era was characterized by different threat models and less mature defense mechanisms compared to contemporary standards.


Published

2009-10-13T10:30:00.627

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom anti-virus 2007 Yes
Application broadcom anti-virus 2008 Yes
Application broadcom anti-virus_for_the_enterprise 7.1 Yes
Application broadcom anti-virus_for_the_enterprise r8 Yes
Application broadcom anti-virus_sdk * Yes
Application broadcom common_services 11 Yes
Application broadcom common_services 11.1 Yes
Application broadcom etrust_antivirus 7.1 Yes
Application broadcom etrust_antivirus 8 Yes
Application broadcom etrust_antivirus 8.1 Yes
Application broadcom etrust_integrated_threat_management 8.1 Yes
Application broadcom etrust_intrusion_detection 3.0 Yes
Application broadcom etrust_secure_content_manager 1.1 Yes
Application broadcom internet_security_suite * Yes
Application broadcom internet_security_suite 3.0 Yes
Application broadcom network_and_systems_management r3.0 Yes
Application broadcom network_and_systems_management r3.1 Yes
Application broadcom network_and_systems_management r11 Yes
Application broadcom network_and_systems_management r11.1 Yes
Application broadcom secure_content_manager 1.1 Yes
Application broadcom secure_content_manager 8.0 Yes
Application broadcom unicenter_network_and_systems_management 3.0 Yes
Application broadcom unicenter_network_and_systems_management 3.1 Yes
Application broadcom unicenter_network_and_systems_management 11 Yes
Application broadcom unicenter_network_and_systems_management 11.1 Yes
Application ca anti-virus 2009 Yes
Application ca anti-virus_for_the_enterprise r8.1 Yes
Application ca anti-virus_gateway 7.1 Yes
Application ca anti-virus_plus 2009 Yes
Application ca arcserve_for_windows_client_agent * Yes
Application ca arcserve_for_windows_server_component * Yes
Application ca common_services 3.1 Yes
Application ca etrust_anti-virus_gateway 7.1 Yes
Application ca etrust_anti-virus_sdk * Yes
Application ca etrust_ez_antivirus r7.1 Yes
Application ca etrust_intrusion_detection 2.0 Yes
Application ca etrust_intrusion_detection 3.0 Yes
Application ca etrust_secure_content_manager 8.0 Yes
Application ca gateway_security r8.1 Yes
Application ca internet_security_suite_2008 * Yes
Application ca internet_security_suite_plus_2008 * Yes
Application ca internet_security_suite_plus_2009 * Yes
Application ca protection_suites r2 Yes
Application ca protection_suites r3 Yes
Application ca protection_suites r3.1 Yes
Application ca threat_manager 8.1 Yes
Application ca threat_manager r8 Yes
Application ca threat_manager_total_defense * Yes
Application broadcom arcserve_backup r12.0 Yes
Application broadcom arcserve_backup r12.0 Yes
Application ca arcserve_backup r11.5 Yes
Operating System microsoft windows * No
Application ca arcserve_backup r11.1 Yes
Application ca arcserve_backup r11.5 Yes
Operating System linux linux_kernel - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For broadcom's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.