Vulnerability CVE-2011-2667


Published: 2011-07-28   Modified: 2012-02-13

Description:
Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.

See advisories in our WLB2 database:
Topic
Author
Date
High
CA Gateway Security and Total Defense
Kotas, Kevin J
01.08.2011

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
CA -> Gateway security 
CA -> Total defense 

 References:
http://securityreason.com/securityalert/8316
http://securitytracker.com/id?1025812
http://securitytracker.com/id?1025813
http://www.securityfocus.com/archive/1/518934/100/0/threaded
http://www.securityfocus.com/archive/1/518935/100/0/threaded
http://www.securityfocus.com/bid/48813
http://www.zerodayinitiative.com/advisories/ZDI-11-237/
https://exchange.xforce.ibmcloud.com/vulnerabilities/68736

Copyright 2024, cxsecurity.com

 

Back to Top