|
eEye Digital Security released an advisory which specified several vulnerable commands in CA License Manager: LOG1, GETCONFIG, PUTOLF, GCR, GBR, OLFCONFIRM, GETBACKUP, GETLOG, NEWOLF, and GETSERVER. Also, any invalid command can be issued to trigger a buffer overflow.
iDefense released some advisories which elaborated on specific attacks against some of these commands, specifically GETCONFIG and PUTOLF, as well as the unchecked buffer for invalid commands.
CA credits both eEye and iDefense with discovery of this vulnerability.
|