Computer Associates Message Queuing Denial Of Service Vulnerability
BID:14621
Info
Computer Associates Message Queuing Denial Of Service Vulnerability
| Bugtraq ID: | 14621 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-2667 CVE-2005-2667 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2005 12:00AM |
| Updated: | Mar 19 2015 08:28AM |
| Credit: | The discoverer of this vulnerability is currently unknown. The vendor disclosed this vulnerability. |
| Vulnerable: |
Computer Associates Unicenter TNG JPN 2.2 Computer Associates Unicenter TNG 2.4.2 Computer Associates Unicenter TNG 2.4 Computer Associates Unicenter TNG 2.2 Computer Associates Unicenter TNG 2.1 Computer Associates Unicenter Software Delivery 4.0 SP1 Computer Associates Unicenter Software Delivery 4.0 Computer Associates Unicenter Software Delivery 3.1 SP2 Computer Associates Unicenter Software Delivery 3.1 SP1 Computer Associates Unicenter Software Delivery 3.1 Computer Associates Unicenter Software Delivery 3.0 Computer Associates Unicenter Service Level Management 3.5 Computer Associates Unicenter Service Level Management 3.0.2 Computer Associates Unicenter Service Level Management 3.0.1 Computer Associates Unicenter Service Level Management 3.0 Computer Associates Unicenter Remote Control 6.0 SP1 Computer Associates Unicenter Remote Control 6.0 Computer Associates Unicenter Performance Management for OpenVMS 2.4 SP3 Computer Associates Unicenter NSM Wireless Network Management Option 3.0 Computer Associates Unicenter Network and Systems Management 3.1 Computer Associates Unicenter Network and Systems Management 3.0 Computer Associates Unicenter Management Portal 3.1 Computer Associates Unicenter Management Portal 2.0 Computer Associates Unicenter Management for WebSphere MQ 3.5 Computer Associates Unicenter Management for Web Servers 5.0.1 Computer Associates Unicenter Management for Web Servers 5.0 Computer Associates Unicenter Management for Microsoft Exchange 4.1 Computer Associates Unicenter Management for Microsoft Exchange 4.0 Computer Associates Unicenter Management for Lotus Notes/Domino 4.0 Computer Associates Unicenter Jasmine 3.0 Computer Associates Unicenter Enterprise Job Manager 1.0 SP2 Computer Associates Unicenter Enterprise Job Manager 1.0 SP1 Computer Associates Unicenter Data Transport Option 2.0 Computer Associates Unicenter Asset Manager Computer Associates Unicenter Asset Management 4.0 Computer Associates Unicenter Asset Management 3.2 SP2 Computer Associates Unicenter Asset Management 3.2 SP1 Computer Associates Unicenter Asset Management 3.2 Computer Associates Unicenter Asset Management 3.1 Computer Associates Unicenter Application Performance Monitor 3.5 Computer Associates Unicenter Application Performance Monitor 3.0 Computer Associates eTrust Admin 8.1 Computer Associates eTrust Admin 8.0 Computer Associates eTrust Admin 2.9 Computer Associates eTrust Admin 2.7 Computer Associates eTrust Admin 2.4 Computer Associates eTrust Admin 2.1 Computer Associates eTrust Admin 2.09 Computer Associates eTrust Admin 2.07 Computer Associates eTrust Admin 2.04 Computer Associates eTrust Admin 2.01 Computer Associates CleverPath Predictive Analysis Server 3.0 Computer Associates CleverPath Predictive Analysis Server 2.0 Computer Associates CleverPath OLAP 5.1 Computer Associates CleverPath ECM 3.5 Computer Associates CleverPath Aion 10.0 Computer Associates CAM 1.11 Computer Associates CAM 1.07 Computer Associates CAM 1.05 Computer Associates BrightStor SAN Manager 11.1 Computer Associates BrightStor SAN Manager 1.1 SP2 Computer Associates BrightStor SAN Manager 1.1 SP1 Computer Associates BrightStor SAN Manager 1.1 Computer Associates BrightStor Portal 11.1 Computer Associates AdviseIT 2.4 Computer Associates Advantage Data Transport 3.0 |
| Not Vulnerable: |
Computer Associates CAM 1.11 Build 29_13 Computer Associates CAM 1.07 Build 220_13 |
Discussion
Computer Associates Message Queuing Denial Of Service Vulnerability
Computer Associates Message Queuing (CAM) is prone to a remote denial of service vulnerability.
A remote attacker can exploit this vulnerability to deny service to legitimate users.
It should be noted exploitation of this issue does not cause the affected application to consume system resources. The only known consequence is no further connections to the TCP port can take place.
Computer Associates Message Queuing (CAM) is prone to a remote denial of service vulnerability.
A remote attacker can exploit this vulnerability to deny service to legitimate users.
It should be noted exploitation of this issue does not cause the affected application to consume system resources. The only known consequence is no further connections to the TCP port can take place.
Exploit / POC
Computer Associates Message Queuing Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Computer Associates Message Queuing Denial Of Service Vulnerability
Solution:
The vendor has released updates addressing this and other issues.
Computer Associates CAM 1.11
Computer Associates CAM 1.07
Computer Associates CAM 1.05
Solution:
The vendor has released updates addressing this and other issues.
Computer Associates CAM 1.11
-
Computer Associates CAM 1.11 Build 29_13
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_cam111 fixes.asp
Computer Associates CAM 1.07
-
Computer Associates CAM 1.07 Build 220_13
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_cam107 fixes.asp
Computer Associates CAM 1.05
-
Computer Associates CAM 1.07 Build 220_13
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_cam107 fixes.asp
References
Computer Associates Message Queuing Denial Of Service Vulnerability
References:
References:
- CA Message Queuing Security Notice (Computer Associates)
- Vendor Home Page (Computer Associates)
- 32919 - Computer Associates Message Queuing (CAM/CAFT) multiple vulnerabilities ("Williams, James K"
)