|
|
Family: Gain root remotely --> Category: infos
Computer Associates Message Queuing Denial Of Service Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Acertains if the remote CAM service is vulnerable to a DoS
Detailed Explanation for this Vulnerability Test
Synopsis :
It is possible to crash the remote messaging service.
Description :
The remote version of Computer Associates Message Queuing Service
is vulnerable to tow flaws which may lead to a denial of service :
- Improper handling of specially crafted TCP packets on port 4105
- Failure to handle spoofed UDP CAM requests
See also :
http://supportconnectw.ca.com/public/ca_common_docs/camsecurity_notice.asp
Solution :
Computer Associates has released a set of patches for CAM 1.05, 1.07
and 1.11.
Threat Level:
Low / CVSS Base Score : 2.3
(AV:R/AC:L/Au:NR/C:N/I:N/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|