Computer Associates Unicenter TNG Utilities Multiple Remote Buffer Overflow Vulnerabilities

BID:9863

Info

Computer Associates Unicenter TNG Utilities Multiple Remote Buffer Overflow Vulnerabilities

Bugtraq ID: 9863
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Mar 12 2004 12:00AM
Updated: Mar 12 2004 12:00AM
Credit: Discovery of these vulnerabilities has been credited to Dave Aitel <[email protected]>.
Vulnerable: Computer Associates Unicenter TNG 2.4.2
Computer Associates Unicenter TNG 2.4
Not Vulnerable: Computer Associates Unicenter TNG 2.5

Discussion

Computer Associates Unicenter TNG Utilities Multiple Remote Buffer Overflow Vulnerabilities

Several Computer Associates Unicenter TNG utilities have been reported to be prone to multiple remote buffer overflow vulnerabilities. These vulnerabilities likely exist due to a lack of sufficient boundary checks performed on user-supplied data.

It has been reported that these issues are exploitable remotely without prior authentication to potentially have arbitrary code executed with SYSTEM privileges on a vulnerable host.

Exploit / POC

Computer Associates Unicenter TNG Utilities Multiple Remote Buffer Overflow Vulnerabilities

The discoverer of these vulnerabilities has developed an exploit. This exploit is not believed to be in public circulation.

Solution / Fix

Computer Associates Unicenter TNG Utilities Multiple Remote Buffer Overflow Vulnerabilities

Solution:
It has been reported that these vulnerabilities have been addressed in Computer Associates Unicenter TNG version 2.5. Customers are advised to contact the vendor regarding obtaining updates.

References

Computer Associates Unicenter TNG Utilities Multiple Remote Buffer Overflow Vulnerabilities

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report