PT-2006-4118 · Ca · Etrust Antivirus+2
Published
2006-06-27
·
Updated
2021-04-09
·
CVE-2006-3223
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CA Integrated Threat Management (ITM) version r8
eTrust Antivirus (eAV) version r8
eTrust PestPatrol (ePP) version r8
Description
The issue allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a scan job with format strings in the
description field. This can be achieved by including format strings in the description field of a scan job.Recommendations
For CA Integrated Threat Management (ITM) version r8, consider restricting the use of format strings in the description field of scan jobs until a fix is available.
For eTrust Antivirus (eAV) version r8, avoid using format strings in the description field of scan jobs to minimize the risk of exploitation.
For eTrust PestPatrol (ePP) version r8, temporarily disable the ability to include format strings in scan job descriptions as a mitigation measure.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ca Integrated Threat Management
Etrust Antivirus
Etrust Pestpatrol