|
Family: Gain root remotely --> Category: infos
Computer Associates Message Queuing Buffer Overflow Vulnerability Vulnerability Scan
Vulnerability Scan Summary Acertains if the remote CAM service is vulnerable to a buffer overflow
Detailed Explanation for this Vulnerability Test
Synopsis :
Arbitrary code can be executed on the remote host due to a flaw in the
CAM service.
Description :
The remote version of Computer Associates Message Queuing Service
contains a a stack overflow in the 'log_security' function that may
allow a possible hacker to execute arbitrary code on the remote host.
This version is also prone to denial of service on the TCP port 4105
as well as arbitrary code execution through spoofed CAFT packets.
A possible hacker does not need to be authenticated to exploit this flaw.
See also :
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_notice.asp
Solution :
Computer Associates has released a set of patches for CAM 1.05, 1.07
and 1.11.
Threat Level:
Critical / CVSS Base Score : 10
(AV:R/AC:L/Au:NR/C:C/A:C/I:C/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|