Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities
BID:24947
Info
Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 24947 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3825 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2007 12:00AM |
| Updated: | Jul 23 2007 07:56PM |
| Credit: | iDefense Labs disclosed this vulnerability to Computer Associates. |
| Vulnerable: |
Computer Associates Protection Suites r3 Computer Associates eTrust Integrated Threat Management 8.0 Computer Associates eTrust Antivirus r8 Computer Associates BrightStor ARCserve Backup for Windows (All) 11.1 Computer Associates BrightStor ARCServe Backup 11.1 Computer Associates BrightStor ARCServe Backup 9.01 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates BrightStor ARCServe Backup 11 Computer Associates BrightStor ARCServe Backup 10.5 Computer Associates Anti-Virus for the Enterprise r8 |
| Not Vulnerable: | |
Discussion
Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities
Computer Associates Alert Notification Server is prone to multiple buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into insufficiently sized buffers.
An attacker can exploit these issues to execute arbitrary code with SYSTEM privileges. Failed exploit attempts likely result in a denial-of-service condition.
This issue affects CA products that rely on the Alert Server; the list of known affected products is as follows:
CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) r8
CA Protection Suites r3
BrightStor ARCserve Backup r11.5
BrightStor ARCserve Backup r11.1
BrightStor ARCserve Backup r11 for Windows
BrightStor Enterprise Backup r10.5
BrightStor ARCserve Backup v9.01
BrightStor ARCserve Client agent for Windows
CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8
Computer Associates Alert Notification Server is prone to multiple buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into insufficiently sized buffers.
An attacker can exploit these issues to execute arbitrary code with SYSTEM privileges. Failed exploit attempts likely result in a denial-of-service condition.
This issue affects CA products that rely on the Alert Server; the list of known affected products is as follows:
CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) r8
CA Protection Suites r3
BrightStor ARCserve Backup r11.5
BrightStor ARCserve Backup r11.1
BrightStor ARCserve Backup r11 for Windows
BrightStor Enterprise Backup r10.5
BrightStor ARCserve Backup v9.01
BrightStor ARCserve Client agent for Windows
CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8
Exploit / POC
Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities
Solution:
Computer Associates has provided an update to address these vulnerabilities. Please see CA document QO89817 and the other vendor references for details.
Solution:
Computer Associates has provided an update to address these vulnerabilities. Please see CA document QO89817 and the other vendor references for details.
References
Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabilities
References:
References:
- [CAID 35515]: CA Products Alert Service RPC Procedure Buffer Overflow Vulnerabil ('Williams, James K'
) - iDefense Security Advisory 07.17.07: Computer Associates Alert Notification ([email protected])
- Computer Associates Alert Notification Server Multiple Buffer Overflow Vulnerabi (iDefense Labs)
- QO89817 (Computer Associates)
- Security Notice for CA products running the Alert service (Computer Associates)