Vulnerabilities > CVE-2005-1693
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve Backup (BAB) r11.1, Vet Antivirus, Zonelabs ZoneAlarm Security Suite, and ZoneAlarm Antivirus, allows remote attackers to gain privileges via a compressed VBA directory with a project name length of -1, which leads to a heap-based buffer overflow.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | CA_VET_OVERFLOW.NASL |
description | The remote host is running a version of CA Vet Scan Engine that is vulnerable to heap overflow. An attacker may exploit this flaw to execute arbitrary code on the remote host with the privileges of a local administrator or to disable the remote service remotely. To exploit this flaw, an attacker would need to send a specially- crafted file to the remote antivirus library. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20174 |
published | 2005-11-09 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20174 |
title | CA Vet Scan Engine < 11.9.1 Library Remote Heap Overflow |
code |
|
References
- http://crm.my-etrust.com/login.asp?username=guest&target=DOCUMENT&openparameter=1588
- http://marc.info/?l=bugtraq&m=111686576416450&w=2
- http://secunia.com/advisories/15470
- http://secunia.com/advisories/15479
- http://securitytracker.com/id?1014050
- http://www.rem0te.com/public/images/vet.pdf
- http://www.securityfocus.com/bid/13710
- http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=32896