Computer Associates ETrust Intrusion Detection Caller.DLL Remote Code Execution Vulnerability
BID:25050
Info
Computer Associates ETrust Intrusion Detection Caller.DLL Remote Code Execution Vulnerability
| Bugtraq ID: | 25050 |
| Class: | Design Error |
| CVE: |
CVE-2007-3302 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2007 12:00AM |
| Updated: | Jul 27 2007 03:35PM |
| Credit: | Sebastian Apelt is credited with the discovery of this vulnerability. |
| Vulnerable: |
Computer Associates eTrust Intrusion Detection 3.0 SP 1 Computer Associates eTrust Intrusion Detection 3.0 |
| Not Vulnerable: | |
Discussion
Computer Associates ETrust Intrusion Detection Caller.DLL Remote Code Execution Vulnerability
Computer Associates eTrust Intrusion Detection is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Computer Associates eTrust Intrusion Detection is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
Computer Associates ETrust Intrusion Detection Caller.DLL Remote Code Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Computer Associates ETrust Intrusion Detection Caller.DLL Remote Code Execution Vulnerability
Solution:
The vendor released patches to address this issue. Please see the references for more information.
Computer Associates eTrust Intrusion Detection 3.0 SP 1
Computer Associates eTrust Intrusion Detection 3.0
Solution:
The vendor released patches to address this issue. Please see the references for more information.
Computer Associates eTrust Intrusion Detection 3.0 SP 1
-
Computer Associates QO89881
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO89 881
Computer Associates eTrust Intrusion Detection 3.0
-
Computer Associates QO89893
http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO89 893
References
Computer Associates ETrust Intrusion Detection Caller.DLL Remote Code Execution Vulnerability
References:
References:
- Computer Associates Homepage (Computer Associates)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- [CAID 35524]: CA eTrust Intrusion Detection caller.dll Vulnerability (Computer Associates)
- iDefense Security Advisory 07.24.07: Computer Associates eTrust Intrusion Detect ([email protected])
- Computer Associates eTrust Intrusion Detection CallCode ActiveX Control Code Exe (iDefense Labs)
- Security Notice for eTrust Intrusion Detection caller.dll vulnerability (Computer Associates)