Home > Support > Global Security Advisor 

Vulnerability Detail

Computer Associates License software multiple buffer overflow vulnerabilities

Date Discovered:
2 Mar 2005

Date Published:
2 Mar 2005

Last Updated:
2 May 2005

Threat Assessment

Overall Risk:  High
Popularity : High
Impact:  Critical
Simplicity:  High

Characteristics

Vulnerability ID:  32058
Discovered By:  iDEFENSE, eEYE

Exploitable Locally:  No
Exploitable Remotely:  Yes

Impact:  Remote attackers can execute arbitrary code.

Root Cause:  Software Vulnerability

 

Description

Computer Associates License software contains multiple buffer overflow vulnerabilities that may allow remote attackers to execute arbitrary code. The vulnerabilities are due to improper bounds checking performed by the License software. Remote attackers can exploit these vulnerabilities to overflow multiple buffers and execute arbitrary code with local SYSTEM privileges. This issue can be remediated by following the instructions at: http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp.

Back to top

Recommendations



-------------------------------------------------------------------------------
For: Computer Associates License Software 1.53 Windows, Computer Associates License Software 1.54.0 Windows, Computer Associates License Software 1.55.0 Windows, Computer Associates License Software 1.56.0 Windows, Computer Associates License Software 1.57.0 Windows, Computer Associates License Software 1.60.0 Windows, Computer Associates License Software 1.60.2 Windows, Computer Associates License Software 1.60.3 Windows, Computer Associates License Software 1.61.0 Windows, Computer Associates License Software 1.61.1 Windows, Computer Associates License Software 1.61.2 Windows, Computer Associates License Software 1.61.8 Windows
Apply: Computer Associates License Software 1.61.12 Windows

Download:
ftp://ftp.ca.com/pub/License98/LicenseIT/lic98_v161/CALicAutoInstall/1-61-12/lic98_win_eng_1-61-12.exe


-------------------------------------------------------------------------------
For: Computer Associates License Software 1.53 AIX, Computer Associates License Software 1.53 HP-UX, Computer Associates License Software 1.53 Red Hat Linux, Computer Associates License Software 1.53 Solaris, Computer Associates License Software 1.53 SuSE Linux, Computer Associates License Software 1.54 AIX, Computer Associates License Software 1.54 HP-UX, Computer Associates License Software 1.54 Red Hat Linux, Computer Associates License Software 1.54 Solaris, Computer Associates License Software 1.54 SuSE, Computer Associates License Software 1.55 AIX, Computer Associates License Software 1.55 HP-UX, Computer Associates License Software 1.55 Red Hat Linux, Computer Associates License Software 1.55 Solaris, Computer Associates License Software 1.55 SuSE Linux, Computer Associates License Software 1.56 AIX, Computer Associates License Software 1.56 HP-UX, Computer Associates License Software 1.56 Red Hat Linux, Computer Associates License Software 1.56 Solaris, Computer Associates License Software 1.56 SuSE Linux, Computer Associates License Software 1.57 AIX, Computer Associates License Software 1.57 HP-UX, Computer Associates License Software 1.57 Red Hat Linux, Computer Associates License Software 1.57 Solaris, Computer Associates License Software 1.57 SuSE Linux, Computer Associates License Software 1.60.0 AIX, Computer Associates License Software 1.60.0 HP-UX, Computer Associates License Software 1.60.0 Red Hat Linux, Computer Associates License Software 1.60.0 Solaris, Computer Associates License Software 1.60.0 SuSE Linux, Computer Associates License Software 1.60.2 AIX, Computer Associates License Software 1.60.2 HP-UX, Computer Associates License Software 1.60.2 Red Hat Linux, Computer Associates License Software 1.60.2 Solaris, Computer Associates License Software 1.60.2 SuSE Linux, Computer Associates License Software 1.60.3 AIX, Computer Associates License Software 1.60.3 HP-UX, Computer Associates License Software 1.60.3 Red Hat Linux, Computer Associates License Software 1.60.3 Solaris, Computer Associates License Software 1.60.3 SuSE Linux, Computer Associates License Software 1.61.0 AIX, Computer Associates License Software 1.61.0 HP-UX, Computer Associates License Software 1.61.0 Red Hat Linux, Computer Associates License Software 1.61.0 Solaris, Computer Associates License Software 1.61.0 SuSE Linux, Computer Associates License Software 1.61.1 AIX, Computer Associates License Software 1.61.1 HP-UX, Computer Associates License Software 1.61.1 Red Hat Linux, Computer Associates License Software 1.61.1 Solaris, Computer Associates License Software 1.61.1 SuSE Linux, Computer Associates License Software 1.61.2 AIX, Computer Associates License Software 1.61.2 HP-UX, Computer Associates License Software 1.61.2 Red Hat Linux, Computer Associates License Software 1.61.2 Solaris, Computer Associates License Software 1.61.2 SuSE Linux, Computer Associates License Software 1.61.8 AIX, Computer Associates License Software 1.61.8 HP-UX, Computer Associates License Software 1.61.8 Red Hat Linux, Computer Associates License Software 1.61.8 Solaris, Computer Associates License Software 1.61.8 SuSE Linux, Computer Associates License Software 1.61.9 AIX, Computer Associates License Software 1.61.9 HP-UX, Computer Associates License Software 1.61.9 Red Hat Linux, Computer Associates License Software 1.61.9 Solaris, Computer Associates License Software 1.61.9 SuSE Linux

Apply the patches provided by the vendor:



http://supportconnectw.ca.com/public/reglic/downloads/licensepatch.asp#alp



To determine the version of CA License software on the system, perform one of the following:



1. Obtain the CA License package version:



Windows: The CA license package version can be obtained by checking the file version of lic98version.exe. Right click on lic98version.exe, choose Properties, and then select the Version tab.



Unix/Linux/Mac: Run lic98version from a command prompt to print out the version number and/or write it to lic98version.log.



2. Obtain the version of the vulnerable file:

If the lic98version file does not exist on the system (which may be the case with older versions of the license package), check the version of the affected file itself:



Windows: Obtain the version of lic98rmt.exe by right-clicking on the file, choosing Properties, and then selecting the Version tab. The vulnerability exists if the version is between 0.1.0.15 and 1.4.6.



Unix/Linux/Mac: Run strings licrmt | grep BUILD from a command prompt. The following string format will be returned: "LICAGENT BUILD INFO = /x.x.x/Apr 16 2003/17:13:35", Where x.x.x is the file version. The vulnerability exists if this file version is between v1.0.15 thru v1.4.6.



Note the following default license install directories:

Windows: C:\CA_LIC or C:\Program Files\CA\SharedComponents\CA_LIC

Unix/Linux/Mac: /opt/CA/ca_lic or /opt/CA/SharedComponents/ca_lic



Vendor advisory:

http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp

Back to top

Affected Technologies

Computer Associates: Computer Associates License Software 1.53 AIX
Computer Associates: Computer Associates License Software 1.53 HP-UX
Computer Associates: Computer Associates License Software 1.53 Red Hat Linux
Computer Associates: Computer Associates License Software 1.53 Solaris
Computer Associates: Computer Associates License Software 1.53 SuSE Linux
Computer Associates: Computer Associates License Software 1.53 Windows
Computer Associates: Computer Associates License Software 1.54 AIX
Computer Associates: Computer Associates License Software 1.54 HP-UX
Computer Associates: Computer Associates License Software 1.54 Red Hat Linux
Computer Associates: Computer Associates License Software 1.54 Solaris
Computer Associates: Computer Associates License Software 1.54 SuSE
Computer Associates: Computer Associates License Software 1.54.0 Windows
Computer Associates: Computer Associates License Software 1.55 AIX
Computer Associates: Computer Associates License Software 1.55 HP-UX
Computer Associates: Computer Associates License Software 1.55 Red Hat Linux
Computer Associates: Computer Associates License Software 1.55 Solaris
Computer Associates: Computer Associates License Software 1.55 SuSE Linux
Computer Associates: Computer Associates License Software 1.55.0 Windows
Computer Associates: Computer Associates License Software 1.56 AIX
Computer Associates: Computer Associates License Software 1.56 HP-UX
Computer Associates: Computer Associates License Software 1.56 Red Hat Linux
Computer Associates: Computer Associates License Software 1.56 Solaris
Computer Associates: Computer Associates License Software 1.56 SuSE Linux
Computer Associates: Computer Associates License Software 1.56.0 Windows
Computer Associates: Computer Associates License Software 1.57 AIX
Computer Associates: Computer Associates License Software 1.57 HP-UX
Computer Associates: Computer Associates License Software 1.57 Red Hat Linux
Computer Associates: Computer Associates License Software 1.57 Solaris
Computer Associates: Computer Associates License Software 1.57 SuSE Linux
Computer Associates: Computer Associates License Software 1.57.0 Windows
Computer Associates: Computer Associates License Software 1.60.0 AIX
Computer Associates: Computer Associates License Software 1.60.0 HP-UX
Computer Associates: Computer Associates License Software 1.60.0 Red Hat Linux
Computer Associates: Computer Associates License Software 1.60.0 Solaris
Computer Associates: Computer Associates License Software 1.60.0 SuSE Linux
Computer Associates: Computer Associates License Software 1.60.0 Windows
Computer Associates: Computer Associates License Software 1.60.2 AIX
Computer Associates: Computer Associates License Software 1.60.2 HP-UX
Computer Associates: Computer Associates License Software 1.60.2 Red Hat Linux
Computer Associates: Computer Associates License Software 1.60.2 Solaris
Computer Associates: Computer Associates License Software 1.60.2 SuSE Linux
Computer Associates: Computer Associates License Software 1.60.2 Windows
Computer Associates: Computer Associates License Software 1.60.3 AIX
Computer Associates: Computer Associates License Software 1.60.3 HP-UX
Computer Associates: Computer Associates License Software 1.60.3 Red Hat Linux
Computer Associates: Computer Associates License Software 1.60.3 Solaris
Computer Associates: Computer Associates License Software 1.60.3 SuSE Linux
Computer Associates: Computer Associates License Software 1.60.3 Windows
Computer Associates: Computer Associates License Software 1.61.0 AIX
Computer Associates: Computer Associates License Software 1.61.0 HP-UX
Computer Associates: Computer Associates License Software 1.61.0 Red Hat Linux
Computer Associates: Computer Associates License Software 1.61.0 Solaris
Computer Associates: Computer Associates License Software 1.61.0 SuSE Linux
Computer Associates: Computer Associates License Software 1.61.0 Windows
Computer Associates: Computer Associates License Software 1.61.1 AIX
Computer Associates: Computer Associates License Software 1.61.1 HP-UX
Computer Associates: Computer Associates License Software 1.61.1 Red Hat Linux
Computer Associates: Computer Associates License Software 1.61.1 Solaris
Computer Associates: Computer Associates License Software 1.61.1 SuSE Linux
Computer Associates: Computer Associates License Software 1.61.1 Windows
Computer Associates: Computer Associates License Software 1.61.2 AIX
Computer Associates: Computer Associates License Software 1.61.2 HP-UX
Computer Associates: Computer Associates License Software 1.61.2 Red Hat Linux
Computer Associates: Computer Associates License Software 1.61.2 Solaris
Computer Associates: Computer Associates License Software 1.61.2 SuSE Linux
Computer Associates: Computer Associates License Software 1.61.2 Windows
Computer Associates: Computer Associates License Software 1.61.8 AIX
Computer Associates: Computer Associates License Software 1.61.8 HP-UX
Computer Associates: Computer Associates License Software 1.61.8 Red Hat Linux
Computer Associates: Computer Associates License Software 1.61.8 Solaris
Computer Associates: Computer Associates License Software 1.61.8 SuSE Linux
Computer Associates: Computer Associates License Software 1.61.8 Windows
Computer Associates: Computer Associates License Software 1.61.9 AIX
Computer Associates: Computer Associates License Software 1.61.9 HP-UX
Computer Associates: Computer Associates License Software 1.61.9 Red Hat Linux
Computer Associates: Computer Associates License Software 1.61.9 Solaris
Computer Associates: Computer Associates License Software 1.61.9 SuSE Linux

Back to top

References

Mitre CVE: CAN-2005-0581
Mitre CVE: CAN-2005-0582
Mitre CVE: CAN-2005-0583

Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All
 
 
Page Tools