|
|||||||||||
|
[CAID 35515]: CA Products Alert Service RPC Procedure Buffer Overflow Vulnerabilities
From: Williams, James K <James.Williams(at)ca.com>
Date: Thu Jul 19 2007 - 14:10:40 EDT Title: [CAID 35515]: CA Products Alert Service RPC Procedure Buffer Overflow Vulnerabilities CA Vuln ID (CAID): 35515 CA Advisory Date: 2007-07-17 Reported By: Anonymous researcher working with the iDefense VCP Impact: Remote attacker can cause a denial of service or execute arbitrary code. Summary: Multiple CA products that utilize Alert service functionality contain multiple vulnerabilities. The vulnerabilities, CVE-2007-3825, are due to insufficient bounds checking on received data by certain RPC procedures. An attacker can exploit these buffer overflows to execute arbitrary code or cause service failure. Mitigating Factors: None Severity: CA has given these vulnerabilities a High risk rating.
Affected Products:
Threat Management) r8
Affected Platforms:
Status and Recommendation:
How to determine if you are affected:
default, the file is located in the
2. Right click on the file and select Properties. 3. Select the Version tab. 4. If the "alert.exe" file version is less than 8.0.255.0, the installation is vulnerable. Workaround: None
References (URLs may wrap):
Changelog for this advisory:
Customers who require additional information should contact CA Technical Support at http://supportconnect.ca.com. For technical questions or comments related to this advisory, please send email to vuln AT ca DOT com.
If you discover a vulnerability in CA products, please report your
findings to vuln AT ca DOT com, or utilize our "Submit a
Vulnerability" form.
Regards,
CA, 1 CA Plaza, Islandia, NY 11749
Contact http://www.ca.com/us/contact/ This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:09:46 EDT |
||||||||||
|
|||||||||||