Computer Associates Total Defense and Gateway Security Remote Code Execution Vulnerability
BID:48813
Info
Computer Associates Total Defense and Gateway Security Remote Code Execution Vulnerability
| Bugtraq ID: | 48813 |
| Class: | Design Error |
| CVE: |
CVE-2011-2667 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2011 12:00AM |
| Updated: | Jul 20 2011 12:00AM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: |
Computer Associates Gateway Security 8.1 |
| Not Vulnerable: |
Computer Associates Gateway Security 9.0 |
Discussion
Computer Associates Total Defense and Gateway Security Remote Code Execution Vulnerability
Computer Associates Total Defense and Gateway Security are prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code with elevated privileges, completely compromising affected computers.
Total Defense r12 and Gateway Security 8.1 are vulnerable; other versions may also be affected.
Computer Associates Total Defense and Gateway Security are prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code with elevated privileges, completely compromising affected computers.
Total Defense r12 and Gateway Security 8.1 are vulnerable; other versions may also be affected.
Exploit / POC
Computer Associates Total Defense and Gateway Security Remote Code Execution Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
Computer Associates Total Defense and Gateway Security Remote Code Execution Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Computer Associates Total Defense and Gateway Security Remote Code Execution Vulnerability
References:
References:
- Computer Associates Homepage (Computer Associates)
- CA Total Defense Suite Gateway Security Malformed HTTP Packet Remote Code Execut (Zero Day Initiative)
- CA20110720-01: Security Notice for CA Gateway Security and Total Defense (CA)
- Solution Document for RO32642 (CA)