漏洞信息详情
CA eTrust Secure Content Manager HTTP网关服务 多个栈溢出漏洞
- CNNVD编号:CNNVD-200806-081
- 危害等级: 超危
- CVE编号: CVE-2008-2541
- 漏洞类型: 缓冲区溢出
- 发布时间: 2008-06-04
- 威胁类型: 远程
- 更新时间: 2009-02-10
- 厂 商: ca
- 漏洞来源: Sebastian Apelt w...
漏洞简介
eTrust Secure Content Manager(eTrust SCM)是独立、统一的网关解决方案,能够帮助企业从中央管理控制台防范资料窃密以及网络和信息传递威胁。
eTrust SCM运行在8080端口上的HTTP网关服务(icihttp.exe)中存在多个栈溢出漏洞。如果用户发布了FTP服务请求,进程会试图修饰事件处理的内容,在这种情况下如果指定了超长的LIST或PASV命令响应,就会触发栈溢出,导致以SYSTEM权限执行任意指令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
https://support.ca.com/irj/portal/anonymous/SolutionResults?aparNo=QO99987&os=NT&actionID=3
参考网址
来源: support.ca.com
链接:https://support.ca.com/irj/portal/anonymous/SolutionResults?aparNo=QO99987&os=NT&actionID=3
来源: XF
名称: ca-etrust-scm-ftp-bo(42821)
链接:http://xforce.iss.net
来源: XF
名称: ca-etrust-scm-ftp-bo(42821)
链接:http://xforce.iss.net/xforce/xfdb/42821
来源: MISC
链接:http://www.zerodayinitiative.com/advisories/ZDI-08-036
来源: MISC
链接:http://www.zerodayinitiative.com/advisories/ZDI-08-035/
来源: SECTRACK
名称: 1020167
链接:http://www.securitytracker.com/id?1020167
来源: BID
名称: 29528
链接:http://www.securityfocus.com/bid/29528
来源: BUGTRAQ
名称: 20080604 CA Secure Content Manager HTTP Gateway Service FTP Request Vulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/493124/100/0/threaded
来源: BUGTRAQ
名称: 20080604 TPTI-08-05: CA ETrust Secure Content Manager Gateway FTP LIST Stack Overflow Vulnerability链接:http://www.securityfocus.com/archive/1/archive/1/493087/100/0/threaded
来源: BUGTRAQ
名称: 20080604 ZDI-08-035: CA ETrust Secure Content Manager Gateway FTP PASV Stack Overflow Vulnerability链接:http://www.securityfocus.com/archive/1/archive/1/493084/100/0/threaded
来源: BUGTRAQ
名称: 20080604 ZDI-08-036: CA ETrust Secure Content Manager Gateway FTP LIST Stack Overflow
链接:http://www.securityfocus.com/archive/1/archive/1/493082/100/0/threaded
来源: VUPEN
名称: ADV-2008-1741
链接:http://www.frsirt.com/english/advisories/2008/1741/references
来源: www.ca.com
链接:http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36408
来源: SECUNIA
名称: 30518
链接:http://secunia.com/advisories/30518
来源: MISC
链接:http://dvlabs.tippingpoint.com/advisory/TPTI-08-05
受影响实体
- Ca Etrust_secure_content_manager:8.0
补丁
暂无
评论