Computer Associates Multiple Products Data Transport Services Remote Buffer Overflow Vulnerability
BID:35984
Info
Computer Associates Multiple Products Data Transport Services Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 35984 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2026 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2009 12:00AM |
| Updated: | Aug 07 2009 09:24PM |
| Credit: | Orlando Padilla and Peter Silberman of Breakpoint Security working with ZDI/TippingPoint |
| Vulnerable: |
Computer Associates Unicenter Software Delivery 4.0 C3 Computer Associates Unicenter Software Delivery 11.2 C2 Computer Associates Unicenter Software Delivery 11.2 C1 Computer Associates Software Delivery 11.2 SP4 Computer Associates Software Delivery 11.2 C3 Computer Associates IT Client Manager 12 Computer Associates Advantage Data Transport 3.0 C3 |
| Not Vulnerable: | |
Discussion
Computer Associates Multiple Products Data Transport Services Remote Buffer Overflow Vulnerability
Multiple Computer Associates products are prone to a remote buffer-overflow vulnerability because they fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected applications. Failed exploit attempts will likely result in a denial-of-service condition.
The issue affects the following:
CA Software Delivery r11.2 C1
CA Software Delivery r11.2 C2
CA Software Delivery r11.2 C3
CA Software Delivery r11.2 SP4
Unicenter Software Delivery 4.0 C3
CA Advantage Data Transport 3.0 C1
CA IT Client Manager r12
Multiple Computer Associates products are prone to a remote buffer-overflow vulnerability because they fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the affected applications. Failed exploit attempts will likely result in a denial-of-service condition.
The issue affects the following:
CA Software Delivery r11.2 C1
CA Software Delivery r11.2 C2
CA Software Delivery r11.2 C3
CA Software Delivery r11.2 SP4
Unicenter Software Delivery 4.0 C3
CA Advantage Data Transport 3.0 C1
CA IT Client Manager r12
Exploit / POC
Computer Associates Multiple Products Data Transport Services Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Computer Associates Multiple Products Data Transport Services Remote Buffer Overflow Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
References
Computer Associates Multiple Products Data Transport Services Remote Buffer Overflow Vulnerability
References:
References:
- CA Homepage (Computer Associates)
- CA20090806-01: Security Notice for Data Transport Services ("Kotas, Kevin J"
) - ZDI-09-052: CA Unicenter Software Delivery dtscore.dll (ZDI Disclosures
) - CA20090806-01: Security Notice for Data Transport Services (Computer Associates)
- ZDI-09-052 CA Unicenter Software Delivery dtscore.dll Stack Overflow Vulnerabili (Zero Day Initiative)