PT-2007-1553 · Ca · Message Queuing+5
Published
2007-07-26
·
Updated
2021-04-14
·
CVE-2007-0060
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CA Message Queuing software versions prior to 1.11 Build 54 4
Description
The issue is a stack-based buffer overflow in the Message Queuing Server (Cam.exe) that allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104. This affects various CA products, including CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products.
Recommendations
For CA Message Queuing software versions prior to 1.11 Build 54 4, update to version 1.11 Build 54 4 or later to resolve the issue. As a temporary workaround, consider restricting access to TCP port 3104 to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brightstor
Ca Advantage Data Transport
Message Queuing
Cleverpath
Unicenter
Etrust Admin