This application requires Javascript for optimal performance.

Computer.Associates.License.GCR.String.Buffer.Overflow

Alias(es)

Computer.Associates.License.GCR.String.BufferOverflow

Release Date

Oct 19, 2006

Severity

critical

Impact

Gain Access

Description

Computer Associates? License Server and License Server and Client has a stack-base buffer overflow. A attacker can execute arbitrary code on the system with the LocalSystem or root privileges via a GCR (GETCONFIG) request with too long IP address, hostname, or netmask string in the NETWORK parameter.

Affected Products

Computer Associates License ServerClient 1.53 to 1.61.8

Recommended Actions

Apply the appropriate patch for your system.
http://supportconnectw.ca.com/public/reglic/downloads/licensepatch.asp#alp

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-0581

Reference/s

http://www.securityfocus.com/bid/12705 (BugTraq)

Reference: VID-13392