Computer Associates Alert Notification Server Multiple Remote Buffer Overflow Vulnerabilities
BID:28605
Info
Computer Associates Alert Notification Server Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 28605 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-4620 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2008 12:00AM |
| Updated: | Apr 04 2008 11:19PM |
| Credit: | An anonymous researcher |
| Vulnerable: |
Computer Associates Threat Manager for the Enterprise r8.1 Computer Associates Threat Manager for the Enterprise r8 Computer Associates BrightStor ARCServe Backup for Windows 11.0 Computer Associates BrightStor ARCServe Backup 11.5 Computer Associates BrightStor ARCServe Backup 11 Computer Associates Anti-Virus for the Enterprise r8.1 Computer Associates Anti-Virus for the Enterprise r8 Computer Associates Anti-Virus for the Enterprise 7.1 |
| Not Vulnerable: | |
Discussion
Computer Associates Alert Notification Server Multiple Remote Buffer Overflow Vulnerabilities
Computer Associates Alert Notification Server is prone to multiple remote buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
Successfully exploiting these issues allows remote attackers to execute arbitrary machine code with SYSTEM-level privileges. This will result in a complete compromise of affected computers.
Computer Associates Alert Notification Server is prone to multiple remote buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied input before copying it into an insufficiently sized memory buffer.
Successfully exploiting these issues allows remote attackers to execute arbitrary machine code with SYSTEM-level privileges. This will result in a complete compromise of affected computers.
Exploit / POC
Computer Associates Alert Notification Server Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Computer Associates Alert Notification Server Multiple Remote Buffer Overflow Vulnerabilities
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
Computer Associates Alert Notification Server Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- Computer Associates Homepage (Computer Associates)
- CA Alert Notification Server Multiple Vulnerabilities ("Williams, James K"
) - iDefense Security Advisory 04.03.08: Computer Associates Alert Notification Serv (iDefense Labs
) - Computer Associates Alert Notification Service Multiple RPC Buffer Overflow Vuln (iDefense)
- Security Notice for Alert Notification Server (Computer Associates)