CA-MLink MLLock Command Line Buffer Overflow Vulnerability
BID:4441
Info
CA-MLink MLLock Command Line Buffer Overflow Vulnerability
| Bugtraq ID: | 4441 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 05 2002 12:00AM |
| Updated: | Apr 05 2002 12:00AM |
| Credit: | Vulnerability discovery credited to KF <[email protected]>. |
| Vulnerable: |
Computer Associates CA-MLINK |
| Not Vulnerable: | |
Discussion
CA-MLink MLLock Command Line Buffer Overflow Vulnerability
CA-MLINK is a data transport management system distributed and maintained by Computer Associates. It is designed for use on the Unix and Microsoft Windows platforms.
The mllock program does not perform adequate bounds checking. Because of this, it is possible to create a buffer overflow on the command line by supplying an arbitrarily long argv. This could result in the overwriting of stack variables, including the return address, and the execution of arbitrary code.
CA-MLINK is a data transport management system distributed and maintained by Computer Associates. It is designed for use on the Unix and Microsoft Windows platforms.
The mllock program does not perform adequate bounds checking. Because of this, it is possible to create a buffer overflow on the command line by supplying an arbitrarily long argv. This could result in the overwriting of stack variables, including the return address, and the execution of arbitrary code.
Exploit / POC
CA-MLink MLLock Command Line Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
CA-MLink MLLock Command Line Buffer Overflow Vulnerability
Solution:
A fix is available:
Computer Associates CA-MLINK
Solution:
A fix is available:
Computer Associates CA-MLINK
-
Computer Associates mlink13.tar
ftp://ftp.ca.com/caproducts/unicenter/mlink/mlink.13/mlink13.tar