Computer Associates Multiple Products Remote Stack Buffer Overflow Vulnerability
TITLE: Computer Associates Multiple Products Remote Stack Buffer Overflow Vulnerability
CLASS: Boundary Condition Error
CVE: CVE-2007-2864
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 05 2007 12:00AM
UPDATE: Jun 07 2007 05:20PM
CREDIT: An anonymous researcher is credited with the discovery of this issue.
VULNERABLE:
Computer Associates Unicenter Network and Systems Management 3.1NOT VULNERABLE:
Computer Associates Unicenter Network and Systems Management 3.0
Computer Associates Unicenter Network and Systems Management 11.1
Computer Associates Unicenter Network and Systems Management 11
Computer Associates Protection Suites r2 0
Computer Associates Protection Suites r3
Computer Associates Internet Security Suite 2007 3.0
Computer Associates Internet Security Suite 2.0
Computer Associates Internet Security Suite 1.0
Computer Associates Integrated Threat Management r8
Computer Associates eTrust Secure Content Manager 8.0
Computer Associates eTrust EZ Armor 3.1
Computer Associates eTrust EZ Armor 3.0
Computer Associates eTrust EZ Armor 2.0
Computer Associates eTrust EZ Armor 1.0
Computer Associates eTrust EZ Antivirus 7.0
Computer Associates eTrust EZ Antivirus 6.1
Computer Associates eTrust Antivirus for the Gateway 7.1
Computer Associates eTrust Antivirus r8.1
Computer Associates eTrust Antivirus r8
Computer Associates Common Services 3.0
Computer Associates Common Services 2.2
Computer Associates Common Services 2.1
Computer Associates Common Services 2.0
Computer Associates Common Services 1.1
Computer Associates Common Services 1.0
Computer Associates BrightStor ARCServe Backup 11.5
Computer Associates BrightStor ARCServe Backup 11.1
Computer Associates BrightStor ARCServe Backup 9.01
Computer Associates BrightStor ARCServe Backup 11
Computer Associates BrightStor ARCServe Backup 10.5
Computer Associates Anti-Virus SDK 0
Computer Associates Anti-Virus 2007 8
Vai alla pagina originale su Security Focus
Discussion
Multiple Computer Associates products are prone to a remote stack-based buffer-overflow vulnerability because the scan engine fails to properly bounds-check user-supplied data before copying it to an insufficiently sized buffer.
A successful exploit will allow an attacker to execute arbitrary code with SYSTEM-level privileges.
Exploit
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:vuldb@securityfocus.com.
Solution
Solution:
The vendor has released content update 30.6 to address this issue. Please see the references for more information.
References
References:
- Computer Associates Homepage (Computer Associates)
- Security Notice for CA products implementing the Anti-Virus engine (Computer Associates)
- ZDI-07-034 CA Multiple Product AV Engine CAB Filename Parsing Stack Overflow Vul (Zero Day Initiative)
- [CAID 35395, 35396]: CA Anti-Virus Engine CAB File Buffer Overflow Vulnerabiliti (Computer Associates)
- ZDI-07-035: CA Multiple Product AV Engine CAB Header Parsing Stack Overflow Vuln (zdi-disclosures@3com.com)
- Vulnerability Note VU#105105 Computer Associates Anti-Virus engine fails to prop (US-CERT)