Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
BID:20365
Info
Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 20365 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5143 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2006 12:00AM |
| Updated: | Sep 08 2008 03:31PM |
| Credit: | livesploit.com is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Computer Associates Server Protection Suite r2 Computer Associates Business Protection Suite r2 Computer Associates BrightStor Enterprise Backup 10.5 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates BrightStor ARCServe Backup 9.01 |
| Not Vulnerable: | |
Discussion
Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
Multiple Computer Associates products are prone to multiple buffer-overflow vulnerabilities because the applications using an affected library fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Exploiting these issues allows attackers to execute arbitrary machine code within the context of the affected application.
Multiple Computer Associates products are prone to multiple buffer-overflow vulnerabilities because the applications using an affected library fail to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Exploiting these issues allows attackers to execute arbitrary machine code within the context of the affected application.
Exploit / POC
Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor has released fixes for these issues. Please see the references for details on how to obtain and apply fixes.
Computer Associates has released an updated advisory that includes new fixes that must be applied in addition to the fixes released earlier. The vendor has reported that this is required because the original fixes failed to address one of the vulnerabilities.
Solution:
The vendor has released fixes for these issues. Please see the references for details on how to obtain and apply fixes.
Computer Associates has released an updated advisory that includes new fixes that must be applied in addition to the fixes released earlier. The vendor has reported that this is required because the original fixes failed to address one of the vulnerabilities.
References
Computer Associates Products Message Engine RPC Server Multiple Buffer Overflow Vulnerabilities
References:
References:
- Computer Associates Homepage (Computer Associates)
- New Fixes for CA BrightStor ARCserve Backup Multiple Buffer Overflow Vulnerabili (Computer Associates)
- CA Multiple Product DBASVR RPC Server Multiple Buffer Overflow ([email protected])
- CA Multiple Product Message Engine RPC Server Code Execution Vulnerability ([email protected])
- CA BrightStor ARCserve Backup Multiple Buffer Overflow Vulnerabilities (James Williams)
- Important Security Notice for BrightStor ARCserve Backup (Buffer Overrun) (Computer Associates)
- LS-20060313 - Computer Associates BrightStor ARCserve Backup (LSsecurity)
- LS-20060330 - Computer Associates BrightStor ARCserve Backup (LSsecurity)