CA Plugs Message-Queuing Buffer Overflows

執筆者
Ryan Naraine
Ryan Naraine
Published: Aug 22, 2005
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Security flaws in CAs Message Queuing software could put users at risk of denial-of-service and system access attacks, the company warned in an advisory.

The Islandia, N.Y.-based software vendor flagged the vulnerabilities in all versions of the CAM (CA Message Queuing) software prior to v1.07 Build 220_13 and v1.11 Build 29_13 on multiple platforms.

In an alert posted online, Computer Associates International Inc. warned that the flaw opens the CAM TCP port to potential denial-of-service attacks.

In addition, CA said boundary errors in the affected software can be exploited to cause buffer overflows by sending specially crafted packets to the service.

/zimages/4/28571.gifRead morehereabout security holes in CA products.

Security alerts aggregator Secunia Inc. rated the bugs as “moderately critical” and warned that an attacker could successfully exploit the boundary errors to launch arbitrary code.

A third vulnerability was also patched to block a possible attack vector in which a spoofed CAFT (a CA application) could be launched to allow the execution of arbitrary commands with elevated privileges.

/zimages/4/28571.gifComputer Associates acquires Qurb, an anti-spam vendor.Click hereto read more.

CAM is a messaging subcomponent which provides a “store and forward” messaging framework for applications. A number of CA applications use CAM for messaging requirements. CAFT, supplied with CAM, is an application that utilizes CAM for file transfers. CAFT is driven by messages it receives from CAM-enabled applications.

Software patches for the vulnerabilities can be found in this advisory.

Affected products include several versions of CA Advantage Data Transport, CA BrightStor Portal, CA CleverPath, CA eTrust Admin and CA Unicenter.

/zimages/4/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。