Buffer overflow vulnerability in CA Message Queuing Server affects numerous products
Computer Associates has reported a vulnerability in its Message Queuing Server (CAM/CAFT) that affects numerous products. A buffer overflow can be triggered by sending specially crafted packets to TCP port 3104, allowing attackers to inject their own code into the system and execute it with system privileges. The vendor rates the severity of the vulnerability as high.
The bug exists in software versions older than v1.11 Build 54_4. CA specifies CAM versions 1.04, 1.05, 1.06, 1.07, 1.10 and 1.11 (each prior to Build 54_4) as vulnerable versions.
The bug affects the following products under Windows und NetWare:
Advantage Data Transport 3.0
BrightStor SAN Manager 11.1, 11.5
BrightStor Portal 11.1
CleverPath OLAP 5.1
CleverPath ECM 3.5
CleverPath Predictive Analysis Server 2.0, 3.0
CleverPath Aion 10.0
eTrust Admin 2.01, 2.04, 2.07, 2.09, 8.0, 8.1
Unicenter Application Performance Monitor 3.0, 3.5
Unicenter Asset Management 3.1, 3.2, 3.2 SP1, 3.2 SP2, 4.0, 4.0 SP1
Unicenter Data Transport Option 2.0
Unicenter Enterprise Job Manager 1.0 SP1, 1.0 SP2
Unicenter Jasmine 3.0
Unicenter Management for WebSphere MQ 3.5
Unicenter Management for Microsoft Exchange 4.0, 4.1
Unicenter Management for Lotus Notes/Domino 4.0
Unicenter Management for Web Servers 5, 5.0.1
Unicenter NSM 3.0, 3.1
Unicenter NSM Wireless Network Management Option 3.0
Unicenter Remote Control 6.0, 6.0 SP1
Unicenter Service Level Management 3.0, 3.0.1, 3.0.2, 3.5
Unicenter Software Delivery 3.0, 3.1, 3.1 SP1, 3.1 SP2, 4.0, 4.0 SP1
Unicenter TNG 2.1, 2.2, 2.4, 2.4.2
Unicenter TNG JPN 2.2
Products under AIX, AS/400, DG Intel, DG Motorola, DYNIX, HP-UX, IRIX, Linux Intel, Linux s/390, MVS, Open VMS, OS/2, OSF1, Solaris Intel, Solaris Sparc and UnixWare are not vulnerable.
CA has provided the patches QO89945 for Windows and QO89943 for NetWare to fix this hole.
- Computer Associates (CA) Message Queuing buffer overflow, security advisory by ISS
- Security Notice for CA Message Queuing (CAM / CAFT) vulnerability, security advisory by CA