Vulnerabilities > CVE-2005-2668

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
broadcom
ca
critical
nessus
exploit available
metasploit

Summary

Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.

Vulnerable Configurations

Part Description Count
Application
Broadcom
47
Application
Ca
15

Exploit-Db

descriptionCA CAM log_security() Stack Buffer Overflow (Win32). CVE-2005-2668. Remote exploit for windows platform
idEDB-ID:16825
last seen2016-02-02
modified2010-09-20
published2010-09-20
reportermetasploit
sourcehttps://www.exploit-db.com/download/16825/
titleCA CAM log_security Stack Buffer Overflow Win32

Metasploit

descriptionThis module exploits a vulnerability in the CA CAM service by passing a long parameter to the log_security() function. The CAM service is part of TNG Unicenter. This module has been tested on Unicenter v3.1.
idMSF:EXPLOIT/WINDOWS/UNICENTER/CAM_LOG_SECURITY
last seen2020-03-11
modified2017-07-24
published2005-11-27
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2668
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/unicenter/cam_log_security.rb
titleCA CAM log_security() Stack Buffer Overflow (Win32)

Nessus

NASL familyGain a shell remotely
NASL idCACAM_OVERFLOW.NASL
descriptionThe remote version of CA Message Queuing Service contains a stack overflow in the
last seen2020-06-01
modified2020-06-02
plugin id20173
published2005-11-08
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/20173
titleCA Multiple Products Message Queuing Multiple Remote Vulnerabilities

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83148/cam_log_security.rb.txt
idPACKETSTORM:83148
last seen2016-12-05
published2009-11-26
reporterH D Moore
sourcehttps://packetstormsecurity.com/files/83148/CA-CAM-log_security-Stack-Overflow-Win32.html
titleCA CAM log_security() Stack Overflow (Win32)

Saint

bid14622
descriptionComputer Associates Message Queuing
idmisc_cam
osvdb18916
titleca_message_queue
typeremote