Computer Associates Message Queuing Buffer Overflow Vulnerability

BID:14622

Info

Computer Associates Message Queuing Buffer Overflow Vulnerability

Bugtraq ID: 14622
Class: Boundary Condition Error
CVE: CVE-2005-2668
Remote: Yes
Local: Yes
Published: Aug 22 2005 12:00AM
Updated: Nov 15 2007 12:37AM
Credit: The discoverer of this vulnerability is currently unknown. The vendor disclosed this issue.
Vulnerable: Computer Associates Unicenter TNG 2.4.2
Computer Associates Unicenter TNG 2.4
Computer Associates Unicenter TNG 2.2
Computer Associates Unicenter TNG 2.1
Computer Associates Unicenter Software Delivery 4.0 SP1
Computer Associates Unicenter Software Delivery 4.0
Computer Associates Unicenter Software Delivery 3.1 SP2
Computer Associates Unicenter Software Delivery 3.1 SP1
Computer Associates Unicenter Software Delivery 3.1
Computer Associates Unicenter Software Delivery 3.0
Computer Associates Unicenter Service Level Management 3.5
Computer Associates Unicenter Service Level Management 3.0.2
Computer Associates Unicenter Service Level Management 3.0.1
Computer Associates Unicenter Service Level Management 3.0
Computer Associates Unicenter Remote Control 6.0 SP1
Computer Associates Unicenter Remote Control 6.0
Computer Associates Unicenter Performance Management for OpenVMS 2.4 SP3
Computer Associates Unicenter NSM Wireless Network Management Option 3.0
Computer Associates Unicenter Network and Systems Management 3.1
Computer Associates Unicenter Network and Systems Management 3.0
Computer Associates Unicenter Management Portal 3.1
Computer Associates Unicenter Management Portal 2.0
Computer Associates Unicenter Management for WebSphere MQ 3.5
Computer Associates Unicenter Management for Web Servers 5.0.1
Computer Associates Unicenter Management for Web Servers 5.0
Computer Associates Unicenter Management for Microsoft Exchange 4.1
Computer Associates Unicenter Management for Microsoft Exchange 4.0
Computer Associates Unicenter Management for Lotus Notes/Domino 4.0
Computer Associates Unicenter Jasmine 3.0
Computer Associates Unicenter Enterprise Job Manager 1.0 SP2
Computer Associates Unicenter Enterprise Job Manager 1.0 SP1
Computer Associates Unicenter Data Transport Option 2.0
Computer Associates Unicenter Asset Management 4.0 SP1
Computer Associates Unicenter Asset Management 4.0
Computer Associates Unicenter Asset Management 3.2 SP2
Computer Associates Unicenter Asset Management 3.2 SP1
Computer Associates Unicenter Asset Management 3.2
Computer Associates Unicenter Asset Management 3.1
Computer Associates Unicenter Application Performance Monitor 3.5
Computer Associates Unicenter Application Performance Monitor 3.0
Computer Associates eTrust Admin 8.1
Computer Associates eTrust Admin 8.0
Computer Associates eTrust Admin 2.9
Computer Associates eTrust Admin 2.7
Computer Associates eTrust Admin 2.4
Computer Associates eTrust Admin 2.1
Computer Associates CleverPath Predictive Analysis Server 3.0
Computer Associates CleverPath Predictive Analysis Server 2.0
Computer Associates CleverPath OLAP 5.1
Computer Associates CleverPath ECM 3.5
Computer Associates CleverPath Aion 10.0
Computer Associates CAM 1.11
Computer Associates CAM 1.07
Computer Associates CAM 1.05
Computer Associates BrightStor SAN Manager 11.1
Computer Associates BrightStor SAN Manager 1.1 SP2
Computer Associates BrightStor SAN Manager 1.1 SP1
Computer Associates BrightStor SAN Manager 1.1
Computer Associates BrightStor Portal 11.1
Computer Associates AdviseIT 2.4
Computer Associates Advantage Data Transport 3.0
Not Vulnerable: Computer Associates CAM 1.11 Build 29_13
Computer Associates CAM 1.07 Build 220_13

Discussion

Computer Associates Message Queuing Buffer Overflow Vulnerability

Computer Associates Message Queuing (CAM) is prone to a buffer-overflow vulnerability because the application fails to perform proper bounds checking on user-supplied data.

A successful attack can cause the process's execution stack to overflow and may ultimately allow arbitrary code to run in the context of the affected application. This may allow an attacker to escalate their privileges to SYSTEM level.

Exploit / POC

Computer Associates Message Queuing Buffer Overflow Vulnerability

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

An exploit (cacam_logsecurity_win32.pm) as part of the Metasploit Framework has been released.

Solution / Fix

Computer Associates Message Queuing Buffer Overflow Vulnerability

Solution:
The vendor has released updates addressing this and other issues.


Computer Associates CAM 1.11

Computer Associates CAM 1.07

Computer Associates CAM 1.05

References

Computer Associates Message Queuing Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report