CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
BID:19403
Info
CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
| Bugtraq ID: | 19403 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3976 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2006 12:00AM |
| Updated: | Aug 08 2006 08:26PM |
| Credit: | Matt Murphy of Tipping Point discovered this issue. |
| Vulnerable: |
Computer Associates eTrust Antivirus WebScan 1.1.0.1047 |
| Not Vulnerable: |
Computer Associates eTrust Antivirus WebScan 1.1.0.1048 |
Discussion
CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
CA eTrust Antivirus WebScan is prone to a remote code-execution vulnerability because it fails to properly validate parameters supplied to the WebScan ActiveX control.
An attacker could exploit this vulnerability to cause WebScan to install malicious application files from an attacker-specified source. This could result in the execution of arbitrary code.
This issue affects version 1.1.0.1047 and earlier; other versions may also be affected.
CA eTrust Antivirus WebScan is prone to a remote code-execution vulnerability because it fails to properly validate parameters supplied to the WebScan ActiveX control.
An attacker could exploit this vulnerability to cause WebScan to install malicious application files from an attacker-specified source. This could result in the execution of arbitrary code.
This issue affects version 1.1.0.1047 and earlier; other versions may also be affected.
Exploit / POC
CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
Solution:
The vendor has released version 1.1.0.1048 to address this issue; please see the references for vendor advisories and more information.
Computer Associates eTrust Antivirus WebScan 1.1.0.1047
Solution:
The vendor has released version 1.1.0.1048 to address this issue; please see the references for vendor advisories and more information.
Computer Associates eTrust Antivirus WebScan 1.1.0.1047
-
Computer Associates scan.aspx
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
References
CA eTrust Antivirus WebScan Malicious Update Code Execution Vulnerability
References:
References:
- Computer Associates Web Site (Computer Associates)
- TippingPoint Advisory TSRT-06-05 (TippingPoint)
- TSRT-06-05: Computer Associates eTrust AntiVirus WebScan Automatic Update Code E ([email protected])