Computer Associates Scan Job Format String Vulnerability
BID:18689
CVE-2006-3223 |Info
Computer Associates Scan Job Format String Vulnerability
| Bugtraq ID: | 18689 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3223 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 27 2006 12:00AM |
| Updated: | Jun 27 2007 07:38PM |
| Credit: | Deral Heiland is credited with the discovery of this vulnerability. |
| Vulnerable: |
Computer Associates Integrated Threat Management r8 Computer Associates eTrust PestPatrol Anti-spyware Corporate Edition r8 Computer Associates eTrust Antivirus r8 |
| Not Vulnerable: | |
Discussion
Computer Associates Scan Job Format String Vulnerability
Multiple Computer Associates applications are prone to a format-string vulnerability because they fail to properly sanitize user-supplied input. The following applications are vulnerable:
- CA Integrated Threat Management r8
- eTrust Antivirus r8
- eTrust PestPatrol Anti-spyware Corporate Edition r8
A successful attack may crash the application or lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation.
Multiple Computer Associates applications are prone to a format-string vulnerability because they fail to properly sanitize user-supplied input. The following applications are vulnerable:
- CA Integrated Threat Management r8
- eTrust Antivirus r8
- eTrust PestPatrol Anti-spyware Corporate Edition r8
A successful attack may crash the application or lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
Computer Associates Scan Job Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Computer Associates Scan Job Format String Vulnerability
Solution:
The vendor has released software updates to address this issue. Please contact the vendor for more information.
Solution:
The vendor has released software updates to address this issue. Please contact the vendor for more information.
References
Computer Associates Scan Job Format String Vulnerability
References:
References:
- Computer Associates Client GUI Security Update (Computer Associates)
- Computer Associates Format String Vulnerability (Deral Heiland)
- Computer Associates Security Advisory (Computer Associates)
- Layered Defense Advisory: Format String Vuln in CA eTrust ([email protected])