PT-2006-4118 · Ca · Etrust Antivirus+2

Published

2006-06-27

·

Updated

2021-04-09

·

CVE-2006-3223

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CA Integrated Threat Management (ITM) version r8 eTrust Antivirus (eAV) version r8 eTrust PestPatrol (ePP) version r8
Description The issue allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a scan job with format strings in the description field. This can be achieved by including format strings in the description field of a scan job.
Recommendations For CA Integrated Threat Management (ITM) version r8, consider restricting the use of format strings in the description field of scan jobs until a fix is available. For eTrust Antivirus (eAV) version r8, avoid using format strings in the description field of scan jobs to minimize the risk of exploitation. For eTrust PestPatrol (ePP) version r8, temporarily disable the ability to include format strings in scan job descriptions as a mitigation measure.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3223

Affected Products

Ca Integrated Threat Management
Etrust Antivirus
Etrust Pestpatrol