Ingress Database Server Multiple Remote Vulnerabilities
BID:24585
Info
Ingress Database Server Multiple Remote Vulnerabilities
| Bugtraq ID: | 24585 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3334 CVE-2007-3336 CVE-2007-3337 CVE-2007-3338 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 21 2007 12:00AM |
| Updated: | Mar 19 2015 08:36AM |
| Credit: | An anonymous person reported the heap-based buffer-overflow vulnerabilities. Chris Anley of NGSSoftware reported the stack-based buffer-overflow vulnerabilities, pointer-overwrite vulnerabilities and the arbitrary file-overwrite vulnerabilities. |
| Vulnerable: |
Ingres Corporation Ingres Database 2006 0 Ingres Corporation Ingres Database 3.0.3 Ingres Corporation Ingres Database 2.6 Ingres Corporation Ingres Database 2.5 Computer Associates Wily SOA Manager 7.1 Computer Associates Unicenter Workload Control Center 1.0.SP4 Computer Associates Unicenter Workload Control Center 1.0 SP4 Computer Associates Unicenter TNG 2.4.2 Computer Associates Unicenter TNG 2.2 Computer Associates Unicenter TNG 2.4.2J Computer Associates Unicenter Software Delivery 11 Computer Associates Unicenter ServicePlus Service Desk 6.0 Computer Associates Unicenter ServicePlus Service Desk 6.0 SP1 Computer Associates Unicenter ServicePlus Service Desk 5.5 SP3 Computer Associates Unicenter ServicePlus Service Desk 11.2 Computer Associates Unicenter ServicePlus Service Desk 11.1 Computer Associates Unicenter ServicePlus Service Desk 11 Computer Associates Unicenter Service Metric Analysis 3.5 Computer Associates Unicenter Service Metric Analysis 3.0.2 Computer Associates Unicenter Service Metric Analysis 11.1 Computer Associates Unicenter Service Metric Analysis 11 Computer Associates Unicenter Service Intelligence 11 Computer Associates Unicenter Service Delivery 11.0 Computer Associates Unicenter Service Delivery 11.1 Computer Associates Unicenter Service Catalog 11 Computer Associates Unicenter Service Assure 2.2 Computer Associates Unicenter Service Assure 11.1 Computer Associates Unicenter Service Assure 11 Computer Associates Unicenter Remote Control 6.0 Computer Associates Unicenter Remote Control 11 Computer Associates Unicenter Patch Management 11 Computer Associates Unicenter Network and Systems Management 3.1 Computer Associates Unicenter Network and Systems Management 3.0 Computer Associates Unicenter Network and Systems Management 11 Computer Associates Unicenter Management Portal 3.1.1 Computer Associates Unicenter Lightweight Portal 2 Computer Associates Unicenter Job Management Option 11.0 Computer Associates Unicenter Enterprise Job Manager 1.0 SP4 Computer Associates Unicenter Enterprise Job Manager 1.0 SP3 Computer Associates Unicenter Desktop Management Suite 11 Computer Associates Unicenter Desktop and Server Management 11 Computer Associates Unicenter Database Command Center 11.1 Computer Associates Unicenter CA Web Services Distributed Management 3.5 Computer Associates Unicenter CA Web Services Distributed Management 3.11 Computer Associates Unicenter Asset Portfolio Management 11.2.1 Computer Associates Unicenter Asset Portfolio Management 11.0 Computer Associates Unicenter Asset Portfolio Management 11.3 Computer Associates Unicenter Asset Management 11 Computer Associates Unicenter Asset Intelligence 11 Computer Associates Unicenter Advanced Systems Management 11 Computer Associates eTrust Web Access Control 1.0 Computer Associates eTrust Single Sign-On 8.1 Computer Associates eTrust Single Sign-On 8 Computer Associates eTrust Single Sign-On 7 Computer Associates eTrust Secure Content Manager 8.0 Computer Associates eTrust Network Forensics 8.1 Computer Associates eTrust Identity Manager 8.1 Computer Associates eTrust IAM Toolkit 8.1 Computer Associates eTrust IAM Toolkit 8 Computer Associates eTrust IAM Suite 8 Computer Associates eTrust Directory 8.1 Computer Associates eTrust Audit r8 Computer Associates eTrust Admin 8.1 Computer Associates eTrust Admin 8.0 Computer Associates eTrust Admin 8.1 SP2 Computer Associates eTrust Admin 8.1 SP1 Computer Associates DocServer 1.1 Computer Associates CleverPath Predictive Analysis Server 3.0 Computer Associates CleverPath Aion BRE 10.1 Computer Associates CleverPath Aion BPM 10.1 Computer Associates CCS 11 Computer Associates BrightStor Storage Resource Manager 11.5 Computer Associates BrightStor Storage Command Center 11.5 Computer Associates BrightStor Enterprise Backup for Tru64 10.5 Computer Associates BrightStor Enterprise Backup for Solaris 10.5 Computer Associates BrightStor Enterprise Backup for HP 10.5 Computer Associates BrightStor Enterprise Backup for AIX 10.5 Computer Associates BrightStor ARCServe Backup for Linux 11.1 Computer Associates BrightStor ARCServe Backup for Linux 9.0 Computer Associates BrightStor ARCServe Backup 11.1 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates ARCserve Backup for Laptops and Desktops 11.5 Computer Associates AllFusion Harvest Change Manager 7.1 Computer Associates AllFusion Harvest Change Manager 7 Computer Associates AllFusion Enterprise Workbench 7.1 Computer Associates AllFusion Enterprise Workbench 7 Computer Associates AllFusion Enterprise Workbench 1.1 SP1 Computer Associates AllFusion Enterprise Workbench 1.1 Computer Associates Advantage Data Transformer 2.2 |
| Not Vulnerable: | |
Discussion
Ingress Database Server Multiple Remote Vulnerabilities
Ingress Database Server included in CA eTrust Secure Content Manager is prone to multiple remote vulnerabilities, including multiple stack- and heap-based buffer-overflow issues, multiple pointer-overwrite issues, and an arbitrary-file-overwrite issue.
Successful exploits will allow attackers to completely compromise affected computers, including executing arbitrary code with SYSTEM-level privileges and truncating the 'alarkp.def' file.
Ingress Database Server included in CA eTrust Secure Content Manager is prone to multiple remote vulnerabilities, including multiple stack- and heap-based buffer-overflow issues, multiple pointer-overwrite issues, and an arbitrary-file-overwrite issue.
Successful exploits will allow attackers to completely compromise affected computers, including executing arbitrary code with SYSTEM-level privileges and truncating the 'alarkp.def' file.
Exploit / POC
Ingress Database Server Multiple Remote Vulnerabilities
The following proof-of-concept is available:
The following proof-of-concept is available:
Solution / Fix
Ingress Database Server Multiple Remote Vulnerabilities
Solution:
The vendor released patches to address these issues. Please see the references for more information.
Solution:
The vendor released patches to address these issues. Please see the references for more information.
References
Ingress Database Server Multiple Remote Vulnerabilities
References:
References:
- CA Products That Embed Ingres Multiple Vulnerabilities (CA)
- Ingres Database Server Homepage (Ingres Corporation )
- Ingres Security Alert (Computer Associates )
- Ingres Unauthenticated Pointer Overwrite 1 (NGS Software Insight Security Research)
- iDefense Security Advisory 06.21.07: Ingres Database Multiple Heap Corruption Vu ([email protected])
- Ingres stack overflow in uuid_from_char function (NGS Software Insight Security Research)
- Ingres Unauthenticated Pointer Overwrite 2 (NGS Software Insight Security Research)
- Ingres verifydb local stack overflow (NGSSoftware Insight Security Research
) - Ingres wakeup setuid(ingres) file truncation (NGS Software Insight Security Research)
- [CAID 35450, 35451, 35452, 35453]: CA Products That Embed Ingres Multiple Vulne (Williams, James K)
- Critical Risk Vulnerability in Ingres (Pointer Overwrite 2) (NGS Software Insight Security Research)
- Ingres Database Multiple Heap Corruption Vulnerabilities (iDefense Labs )