what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

eleytt-CAvarious.txt

eleytt-CAvarious.txt
Posted Oct 11, 2007
Authored by Michal Bucko | Site eleytt.com

Eleytt has discovered various buffer overflow and denial of service vulnerabilities in CA Erwin, G Data Antivirus, CA eTrust, VMware, and CA eTrust ITM.

tags | advisory, denial of service, overflow, vulnerability
SHA-256 | e744374fb45a8a99ad3791b2ee6d78d682fbc766adfffd201b3e3161c3d5b70e

eleytt-CAvarious.txt

Change Mirror Download

Eleytt Research
www.eleytt.com




Overview:
====================
Michal Bucko, Eleytt, www.eleytt.com/michal.bucko
Tomasz Polis, www.eleytt.com





Credit:
====================

Michal Bucko, Eleytt, www.eleytt.com/michal.bucko







Vulnerability Table
===================

1. CA Erwin Datatype Standards File Denial of
Service Vulnerability
2. G DATA Antivirus SelectPath() ScanObjectBrowser.dll
Buffer Overflow Vulnerability
3. CA eTrust ITM r8.1 Web Console Script Redirection
Vulnerability
4. VMware Virtual Disk Mount Service Local Denial of
Service Vulnerability
5. CA eTrust ITM r8.1 iTechnology SPIN Web Interface
Sensitive Information Disclosure Vulnerability








Vulnerability Details
=========================
=========================



1. CA Erwin Datatype Standards File Denial of
Service Vulnerability
============================================

The vulnerability is caused by improper handling of
certain abnormal conditions. The successful exploitation
leads to CA Erwin's denial of service conditions.




2. G DATA Antivirus ScanObjectBrowser.dll
Buffer Overflow Vulnerability
==============================================

The buffer overflow in ScanObjectBrowser.DLL ActiveX
control (in function SelectPath) might lead to machine
compromise. The vulnerability is not however exploitable
via a web browser as the control is not marked safe for
scripting.




3. CA eTrust ITM r8.1 Web Console Script Redirection
Vulnerability
==================================================

Computer Associates eTrust ITM (Threat Manager) is prone to
remote script redirection. By enticing the unaware victim to
open a specially crafted link (http://localhost:6689/...), an
attacker might lead the victim to a different web site. Such
issues might be used in phishing attacks as the victim does not
suspect such script's behavior.




4. VMware Virtual Disk Mount Service Local Denial of
Service Vulnerability
=================================================

Vmware-provided library Reconfig.DLL (function ConnectPopulatedDiskEx)
is prone to local denial of service vulnerability. The vulnerability
might be used by malware to cause denial of service conditions of
Vmware's Virtual Disk Mount Service (vmount2.exe). The control is not
marked safe for scripting, thus remote exploitation via a web browser
is not possible.




5.CA eTrust ITM r8.1 Web Console Sensitive Information
Disclosure
====================================================

Computer Associates eTrust ITM (Threat Manager) is prone to
remote sensitive information disclosure. Sensitive information
is stored within log files (we can easily deduct the file names),
remote exploitation is possible. The attacker gains information
about the user logging history, user names and various directories.
It might be possible that other imporant information might be stored
in the log file but this has not been confirmed yet.






Meet Our Business Continuity Program!
=====================================


Eleytt offers Eleytt Business Continuity Program. What is it?


- Long-term continous security audits
- Security consulting and training
- Security policy compliance issues


For more information, please refer to eleytt.com, http://www.eleytt.com








Eleytt - Company Information
============================

Eleytt Corporation is specialized in penetration testing, vulnerability
development, advanced reverse engineering and exploitation techniques.
Eleytt provides various security-related services: risk assessment,
security policy, security assurance, incident management, web
application security testing, continuous security assurance programs.
Eleytt provides security audits for financial institutions and e-commerce.
Eleytt provides an in-depth security analysis - experienced security
experts analyze your source code, analyze your application, analyze your
web application. Eleytt runs security programs for financial institutons
and e-commerce.

We have the mission to improve the security level of software and web
applications. It is us who help you implement more secure applications.
We help you understand the risk and deploy security solutions. We help
you avoid costly business disruptions.







These are the questions, which might help you understand how we work:
=====================================================================

Want to get your web site checked for security vulnerabilities?

Your server requires real penetration testing?

Interested in Eleytt Business Continuity Program?

Interested in Eleytt Application Security Program?






For more information, please use:

http://www.eleytt.com









DISCLAIMER
==========

This document and all the information it contains are provided "as is",
for educational purposes only, without warranty of any kind, whether
express or implied.

The authors reserve the right not to be responsible for the topicality,
correctness, completeness or quality of the information provided in
this document. Liability claims regarding damage caused by the use of
any information provided, including any kind of information which is
incomplete or incorrect, will therefore be rejected.

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close