PT-2007-1553 · Ca · Message Queuing+5
Publicado
2007-07-26
·
Atualizado
2021-04-14
·
CVE-2007-0060
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CA Message Queuing software versions prior to 1.11 Build 54 4
Description
The issue is a stack-based buffer overflow in the Message Queuing Server (Cam.exe) that allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104. This affects various CA products, including CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products.
Recommendations
For CA Message Queuing software versions prior to 1.11 Build 54 4, update to version 1.11 Build 54 4 or later to resolve the issue. As a temporary workaround, consider restricting access to TCP port 3104 to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Brightstor
Ca Advantage Data Transport
Message Queuing
Cleverpath
Unicenter
Etrust Admin