Computer Associates Vet Library Remote Heap Overflow Vulnerability
BID:13710
Info
Computer Associates Vet Library Remote Heap Overflow Vulnerability
| Bugtraq ID: | 13710 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-1693 |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Alex Wheeler is credited with the discovery of this vulnerability. |
| Vulnerable: |
Zone Labs ZoneAlarm Security Suite 5.5 .062.011 Zone Labs ZoneAlarm Security Suite 5.5 .062 Zone Labs ZoneAlarm Security Suite 5.5 Zone Labs ZoneAlarm Security Suite 5.1 Zone Labs ZoneAlarm Antivirus Computer Associates Vet Antivirus 10.66 Computer Associates InoculateIT 6.0 Computer Associates eTrust Secure Content Manager 1.1 Computer Associates eTrust Secure Content Manager 1.0 SP1 Computer Associates eTrust Secure Content Manager 1.0 Computer Associates eTrust Intrusion Detection 3.0 SP 1 Computer Associates eTrust Intrusion Detection 3.0 Computer Associates eTrust Intrusion Detection 1.5 Computer Associates eTrust Intrusion Detection 1.4.5 Computer Associates eTrust Intrusion Detection 1.4.1 .13 Computer Associates eTrust EZ Armor LE 3.0 .0.14 Computer Associates eTrust EZ Armor LE 2.0 Computer Associates eTrust EZ Armor 2.4.4 Computer Associates eTrust EZ Armor 2.4 Computer Associates eTrust EZ Armor 2.3 Computer Associates eTrust EZ Armor 2.0 Computer Associates eTrust EZ Armor 1.0 Computer Associates eTrust Antivirus for the Gateway 7.1 Computer Associates eTrust Antivirus for the Gateway 7.0 Computer Associates eTrust Antivirus EE 7.0 Computer Associates eTrust Antivirus EE 6.0 Computer Associates eTrust Antivirus 7.1 Computer Associates eTrust Antivirus 7.0 SP2 Computer Associates eTrust Antivirus 7.0 Computer Associates eTrust Antivirus 6.0 Computer Associates BrightStor ARCserve Backup for Windows (All) 11.1 Computer Associates BrightStor ARCServe Backup for Windows 11.1 |
| Not Vulnerable: |
Computer Associates Vet Antivirus 11.9.1 Computer Associates Vet Antivirus 10.67 Computer Associates eTrust EZ Armor 3.1 |
Discussion
Computer Associates Vet Library Remote Heap Overflow Vulnerability
CA Vet is susceptible to a remote heap overflow vulnerability. This is due to an integer overflow flaw in memory allocation and utilization routines.
This issue presents itself when malicious compressed VBA projects are processed by the library.
This vulnerability allows remote attackers to overwrite critical heap memory control structures. This results in the ability to cause arbitrary machine code to be executed in the context of applications that utilize the affected library.
CA Vet is susceptible to a remote heap overflow vulnerability. This is due to an integer overflow flaw in memory allocation and utilization routines.
This issue presents itself when malicious compressed VBA projects are processed by the library.
This vulnerability allows remote attackers to overwrite critical heap memory control structures. This results in the ability to cause arbitrary machine code to be executed in the context of applications that utilize the affected library.
Exploit / POC
Computer Associates Vet Library Remote Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Computer Associates Vet Library Remote Heap Overflow Vulnerability
Solution:
The vendor has released advisory CAID 32896, along with fixes to address this issue. Computer Associates states that most of the affected products can receive a fix for this vulnerability through utilizing their built-in virus update feature.
Please see the referenced advisory, as well as the referenced Web pages from the vendor for further information on obtaining fixes.
Zone Labs has released an advisory to address this issue in affected products. Users are advised to upgrade the anti-virus engine to version 11.9.1 or subsequent through the Update Now option in the products. Please see the message reference from Zone Labs for more information and specific steps required to upgrade.
Solution:
The vendor has released advisory CAID 32896, along with fixes to address this issue. Computer Associates states that most of the affected products can receive a fix for this vulnerability through utilizing their built-in virus update feature.
Please see the referenced advisory, as well as the referenced Web pages from the vendor for further information on obtaining fixes.
Zone Labs has released an advisory to address this issue in affected products. Users are advised to upgrade the anti-virus engine to version 11.9.1 or subsequent through the Update Now option in the products. Please see the message reference from Zone Labs for more information and specific steps required to upgrade.
References
Computer Associates Vet Library Remote Heap Overflow Vulnerability
References:
References:
- Computer Associates Vet Antivirus engine heap overflow vulnerability (Computer Associates)
- Vet Antivirus (Computer Associates)
- Vulnerability ID: 32896 - CA eTrust EZ Antivirus Document Scanning Engine Vulner (Computer Associates)
- CAID 32896 - Computer Associates Vet Antivirus engine heap overflow vulnerabilit ("Williams, James K"
) - Computer Associates Vet Antivirus Library Remote Heap Overflow ([email protected])
- RE: CAID 32896 - Computer Associates Vet Antivirus engine heap overflow vulnerab (
) - Zone Labs ZoneAlarm Vet anti-virus engine OLE processing vulnerability ("Zone Labs Product Security"
)