|
|||||||||||
|
[CAID 35690, 35691, 35692]: CA BrightStor Hierarchical Storage Manager CsAgent Multiple Vulnerabilities
From: Williams, James K <James.Williams(at)ca.com>
Date: Wed Sep 26 2007 - 22:37:58 EDT Title: [CAID 35690, 35691, 35692]: CA BrightStor Hierarchical Storage Manager CsAgent Multiple Vulnerabilities CA Vuln ID (CAID): 35690, 35691, 35692 CA Advisory Date: 2007-09-26 Reported By: Sean Larsson, iDefense Labs
anonymous researcher working with the iDefense VCP
Aaron Portnoy of DV Labs (dvlabs.tippingpoint.com)
Impact: A remote attacker can execute arbitrary code or cause a denial of service condition. Summary: Multiple vulnerabilities exist in the CsAgent service that can allow a remote attacker to execute arbitrary code or cause a denial of service condition. The first set of vulnerabilities, CVE-2007-5082, occur due to insufficient bounds checking in multiple CsAgent service commands. The second set of vulnerabilities, CVE-2007-5083, occur due to insufficient validation of integer values in multiple CsAgent service commands, which can lead to buffer overflow. The third set of vulnerabilities, CVE-2007-5084, occur due to insufficient validation of strings used in SQL statements in multiple CsAgent service commands.
Mitigating Factors:
Severity: CA has given these vulnerabilities a maximum risk rating of High.
Affected Products:
Affected Platforms:
Status and Recommendation:
How to determine if you are affected:
Workaround: None
References (URLs may wrap):
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35690http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35691http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35692Reported By: Sean Larsson, iDefense Labs; an anonymous researcher working with the iDefense VCP; Aaron Portnoy of DV Labs (dvlabs.tippingpoint.com) iDefense advisory: http://labs.idefense.com/intelligence/vulnerabilities/ ZDI advisory: http://www.zerodayinitiative.com/advisories.html CVE References: CVE-2007-5082, CVE-2007-5083, CVE-2007-5084 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5082http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5083http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5084OSVDB References: Pending http://osvdb.org/
Changelog for this advisory:
Customers who require additional information should contact CA Technical Support at http://supportconnect.ca.com. For technical questions or comments related to this advisory, please send email to vuln AT ca DOT com.
If you discover a vulnerability in CA products, please report your
findings to vuln AT ca DOT com, or utilize our "Submit a
Vulnerability" form.
Regards,
CA, 1 CA Plaza, Islandia, NY 11749
Contact http://www.ca.com/us/contact/ This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:18:10 EDT |
||||||||||
|
|||||||||||