IT Security & Network Security News & Reviews - eWeek



CA Plugs Message-Queuing Buffer Overflows




The software vendor releases patches for "moderately critical" denial-of-service and system access vulnerabilities.

Security flaws in CAs Message Queuing software could put users at risk of denial-of-service and system access attacks, the company warned in an advisory.

The Islandia, N.Y.-based software vendor flagged the vulnerabilities in all versions of the CAM (CA Message Queuing) software prior to v1.07 Build 220_13 and v1.11 Build 29_13 on multiple platforms.

In an alert posted online, Computer Associates International Inc. warned that the flaw opens the CAM TCP port to potential denial-of-service attacks.

In addition, CA said boundary errors in the affected software can be exploited to cause buffer overflows by sending specially crafted packets to the service.

Read more here about security holes in CA products.

Security alerts aggregator Secunia Inc. rated the bugs as "moderately critical" and warned that an attacker could successfully exploit the boundary errors to launch arbitrary code.

A third vulnerability was also patched to block a possible attack vector in which a spoofed CAFT (a CA application) could be launched to allow the execution of arbitrary commands with elevated privileges.

Computer Associates acquires Qurb, an anti-spam vendor. Click here to read more.

CAM is a messaging subcomponent which provides a "store and forward" messaging framework for applications. A number of CA applications use CAM for messaging requirements. CAFT, supplied with CAM, is an application that utilizes CAM for file transfers. CAFT is driven by messages it receives from CAM-enabled applications.

Software patches for the vulnerabilities can be found in this advisory.

Affected products include several versions of CA Advantage Data Transport, CA BrightStor Portal, CA CleverPath, CA eTrust Admin and CA Unicenter.

Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.







 
 
>>> More IT Security & Network Security News & Reviews Articles          >>> More By Ryan Naraine
 

FEATURED SPONSOR MESSAGE

Start the New Year with business intelligence—it’s a smart move

Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.

Click Here

Brought to you by


eweek digital



Advertisement
 
APPLY FOR A FREE 
SUBSCRIPTION BELOW:

>Try digital eWEEK
>Renew today
>Subscription help
>More FREE Subscriptions
First Name:Last Name:
Title:Company:
Address:City:
State:Zip Code:
Email:
eWEEK Quick LInks