2007-10-13 / 2007-10-14
Credit: Michal Bucko
Risk: High
Local: Yes
Remote: Yes

Vulnerability Table =================== 1. CA Erwin Datatype Standards File Denial of Service Vulnerability 2. G DATA Antivirus SelectPath() ScanObjectBrowser.dll Buffer Overflow Vulnerability 3. CA eTrust ITM r8.1 Web Console Script Redirection Vulnerability 4. VMware Virtual Disk Mount Service Local Denial of Service Vulnerability 5. CA eTrust ITM r8.1 iTechnology SPIN Web Interface Sensitive Information Disclosure Vulnerability Vulnerability Details ========================= ========================= 1. CA Erwin Datatype Standards File Denial of Service Vulnerability ============================================ The vulnerability is caused by improper handling of certain abnormal conditions. The successful exploitation leads to CA Erwin's denial of service conditions. 2. G DATA Antivirus ScanObjectBrowser.dll Buffer Overflow Vulnerability ============================================== The buffer overflow in ScanObjectBrowser.DLL ActiveX control (in function SelectPath) might lead to machine compromise. The vulnerability is not however exploitable via a web browser as the control is not marked safe for scripting. 3. CA eTrust ITM r8.1 Web Console Script Redirection Vulnerability ================================================== Computer Associates eTrust ITM (Threat Manager) is prone to remote script redirection. By enticing the unaware victim to open a specially crafted link (http://localhost:6689/...), an attacker might lead the victim to a different web site. Such issues might be used in phishing attacks as the victim does not suspect such script's behavior. 4. VMware Virtual Disk Mount Service Local Denial of Service Vulnerability ================================================= Vmware-provided library Reconfig.DLL (function ConnectPopulatedDiskEx) is prone to local denial of service vulnerability. The vulnerability might be used by malware to cause denial of service conditions of Vmware's Virtual Disk Mount Service (vmount2.exe). The control is not marked safe for scripting, thus remote exploitation via a web browser is not possible. 5.CA eTrust ITM r8.1 Web Console Sensitive Information Disclosure ==================================================== Computer Associates eTrust ITM (Threat Manager) is prone to remote sensitive information disclosure. Sensitive information is stored within log files (we can easily deduct the file names), remote exploitation is possible. The attacker gains information about the user logging history, user names and various directories. 