OSVDB ID: 34586

Title: CA Multiple Products InoCore.dll File Mapping Manipulation Local Overflow

Info

Disclosure

May 09, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

May 12, 2007

Description

A buffer overflow exists in multiple CA products. InoCore.dll fails to validate file mappings resulting in a stack overflow. With a specially crafted file mapping, a local attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Private, Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, CA has released a patch to address this vulnerability.

Products

CA

Anti-Virus for the Enterprise

r8

Threat Manager for the Enterprise

r8

References

Credit

  • binagres -


Direct URL: http://osvdb.org/34586