Lucene search

K
saintSAINT CorporationSAINT:88240953BD9A7A01C8C6A3DFE05B54A7
HistoryJun 07, 2007 - 12:00 a.m.

CA Antivirus engine CAB handling buffer overflow

2007-06-0700:00:00
SAINT Corporation
download.saintcorporation.com
7

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.945 High

EPSS

Percentile

99.2%

Added: 06/07/2007
CVE: CVE-2007-2864
BID: 24330
OSVDB: 35245

Background

The CA Antivirus engine is included in multiple CA products.

Problem

A buffer overflow vulnerability in the CA Antivirus engine allows command execution when a CAB file containing a specially crafted “coffFiles” field is scanned.

Resolution

Apply content update 30.6 as described in the CA Security Notice.

References

<http://www.zerodayinitiative.com/advisories/ZDI-07-035.html&gt;

Limitations

Exploit works on CA eTrust Antivirus 8.1.637 and requires a user to download and open the exploit file.

Platforms

Windows

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.945 High

EPSS

Percentile

99.2%