Home > Support > Global Security Advisor 

Vulnerability Detail

Computer Associates Vet Antivirus engine heap overflow vulnerability

Date Discovered:
23 May 2005

Date Published:
23 May 2005

Last Updated:
2 Jun 2005

Threat Assessment

Overall Risk:  Medium
Popularity : Medium
Impact:  High
Simplicity:  Medium

Characteristics

Vulnerability ID:  32896
Discovered By:  Alex Wheeler

Exploitable Locally:  No
Exploitable Remotely:  Yes

Impact:  Remote attackers can execute arbitrary code.

Root Cause:  Software Vulnerability

 

Description

Computer Associates Vet Antivirus engine contains a vulnerability that may allow remote attackers to execute arbitrary code. The vulnerability is due to improper integer bounds checking performed when analyzing the OLE stream. Remote attackers can exploit this vulnerability using a Microsoft Office document to cause a heap overflow and execute arbitrary code.

Back to top

Recommendations



-------------------------------------------------------------------------------
For: ZoneAlarm Antivirus 5.0, ZoneAlarm Antivirus 5.1, ZoneAlarm Antivirus 5.5, ZoneAlarm Security Suite 5.0, ZoneAlarm Security Suite 5.1, ZoneAlarm Security Suite 5.5

Vet engine 11.9.1 and later are not affected. Install the latest virus defintions if an earier Vet is in use.



1. Open Antivirus



2. In Status, select Update Now

-------------------------------------------------------------------------------
For: eTrust Antivirus 6.0 Linux, eTrust Antivirus 6.0 Notes/Exchange, eTrust Antivirus 6.0 Solaris, eTrust Antivirus 6.0 SP1 Windows NT/2000/XP, eTrust Antivirus 6.0 SP2 Windows NT/2000/XP, eTrust Antivirus 6.0 Windows 95/98/ME, eTrust Antivirus 6.0 Windows NT/2000/XP, eTrust Antivirus 7.0 Notes/Exchange, eTrust Antivirus 7.0 Solaris, eTrust Antivirus 7.0 Windows 95/98/ME, eTrust Antivirus 7.0 Windows NT/2000/XP, eTrust Antivirus 7.1 Notes/Exchange, eTrust Antivirus 7.1 Solaris, eTrust Antivirus 7.1 Windows NT/2000/XP, eTrust Antivirus for the Gateway 7.0, eTrust Antivirus for the Gateway r7.1, eTrust EZ Antivirus 2005(v6.2), eTrust EZ Antivirus 6.0.123, eTrust EZ Antivirus 6.0.125, eTrust EZ Antivirus 6.1, eTrust EZ Antivirus 6.1.0.24, eTrust EZ Antivirus 6.1.3.1, eTrust EZ Antivirus 6.1.4.0, eTrust EZ Antivirus 6.1.5.8, eTrust EZ Antivirus 6.1.7.0, eTrust EZ Antivirus 6.2, eTrust EZ Antivirus 6.2.0.28, eTrust EZ Antivirus 6.3, eTrust EZ Antivirus 6.4, eTrust EZ Antivirus 6.4.0.4, eTrust EZ Antivirus 7, eTrust EZ Antivirus 7.0.0, eTrust EZ Antivirus 7.0.0.33, eTrust EZ Antivirus 7.0.1, eTrust EZ Antivirus 7.0.1.4, eTrust EZ Antivirus 7.0.2, eTrust EZ Antivirus 7.0.2.1, eTrust EZ Antivirus 7.0.3, eTrust EZ Antivirus 7.0.3.1, eTrust EZ Antivirus 7.0.4, eTrust EZ Antivirus 7.0.5, eTrust EZ Antivirus 7.0.5.3, eTrust EZ Antivirus 7.0.6.7, eTrust Intrusion Detection 1.4.1.13, eTrust Intrusion Detection 2.0, eTrust Intrusion Detection 2.0 SP1, eTrust Intrusion Detection 3.0, eTrust Intrusion Detection 3.0 SP1, eTrust Secure Content Manager 1.0, eTrust Secure Content Manager 1.0 SP1, eTrust Secure Content Manager 1.1, EZ Armor 1.0.23, EZ Armor 1.0.24, EZ Armor 1.0.28, EZ Armor 1.0.3, EZ Armor 1.0.6, EZ Armor 2.0, EZ Armor 2.0.13, EZ Armor 2.0.6, EZ Armor 2.3, EZ Armor 2.4, EZ Armor 2.4.4, EZ Armor 3.0.0.13, EZ Armor 3.0.0.16, EZ Armor 3.1, EZ Armor 3.1.0, EZ Armor 3.2, EZ Armor LE 2.0, EZ Armor LE 2.0.13, EZ Armor LE 2.1.16, EZ Armor LE 2.4.5, EZ Armor LE 3.0.0.10, EZ Armor LE 3.0.0.14, InoculateIT 6.0, Vet Antivirus 10.66

CA corporate products, eTrust EZ Antivirus 7.x and eTrust EZ Armor 3.1 have the ability to patch this issue automatically. The patch was rolled out as part of the daily Vet Signature updates on May 3, 2005.



eTrust Antivirus:

Products running Vet engine 11.9.1 or later are not affected by this issue.



eTrust EZ Antivirus:



This issue is addressed with eTrust EZ Antivirus (Vet) Engine 11.9.1 and later.



To determine which engine version you are currently running, right-click on the EZAV or AV icon in your system tray and select "Product Info" or "About" (depending on your product version). Your engine version will be listed in the dialog box that pops up.



To learn how to update your engine, please review the instructions at

http://crm.my-etrust.com/login.asp?username=guest&target=DOCUMENT&openparameter=1588



eTrust EZ Antivirus 6.x:

Upgrade to EZ Antivirus 7.

http://consumerdownloads.ca.com/myeTrust/apps/EZAntivirus.exe



eTrust EZ Armor 3.x:

The patch will be pushed down to affected computers automatically and will require a reboot.



eTrust EZ Armor 2.x:

Upgrade to eTrust EZ Armor 3.1.

http://consumerdownloads.ca.com/myeTrust/apps/EZArmor.exe

Back to top

Affected Technologies

Computer Associates: CA Database Command Center r11.2.4.1.13
Computer Associates: CA eTrust Antivirus 7.1 for Windows
Computer Associates: CA eTrust EZ Antivirus 7
Computer Associates: CA eTrust EZ Antivirus 7.0.0
Computer Associates: CA eTrust EZ Antivirus 7.0.0.33
Computer Associates: CA eTrust EZ Antivirus 7.0.1
Computer Associates: CA eTrust EZ Antivirus 7.0.1.4
Computer Associates: CA eTrust EZ Antivirus 7.0.2
Computer Associates: CA eTrust EZ Antivirus 7.0.2.1
Computer Associates: CA eTrust EZ Antivirus 7.0.3
Computer Associates: CA eTrust EZ Antivirus 7.0.3.1
Computer Associates: CA eTrust EZ Antivirus 7.0.4
Computer Associates: CA eTrust EZ Antivirus 7.0.5
Computer Associates: CA eTrust EZ Antivirus 7.0.5.3
Computer Associates: CA eTrust EZ Antivirus 7.0.6.7
Computer Associates: CA EZ Armor LE 2.0
Computer Associates: CA EZ Armor LE 2.0.13
Computer Associates: CA EZ Armor LE 2.1
Computer Associates: CA EZ Armor LE 2.4
Computer Associates: CA EZ Armor LE 3.0
Computer Associates: CA EZ Armor LE 3.0.0.14
Computer Associates: eTrust Antivirus 6.0 Linux
Computer Associates: eTrust Antivirus 6.0 Notes/Exchange
Computer Associates: eTrust Antivirus 6.0 Solaris
Computer Associates: eTrust Antivirus 6.0 Windows 95/98/ME
Computer Associates: eTrust Antivirus 6.0 Windows NT/2000/XP
Computer Associates: eTrust Antivirus 6.0 Windows NT/2000/XP SP1
Computer Associates: eTrust Antivirus 6.0 Windows NT/2000/XP SP2
Computer Associates: eTrust Antivirus 7.0 Notes/Exchange
Computer Associates: eTrust Antivirus 7.0 Solaris
Computer Associates: eTrust Antivirus 7.0 Windows 95/98/ME
Computer Associates: eTrust Antivirus 7.0 Windows NT/2000/XP
Computer Associates: eTrust Antivirus 7.1 Notes/Exchange
Computer Associates: eTrust Antivirus 7.1 Solaris
Computer Associates: eTrust Antivirus for the Gateway 7.0
Computer Associates: eTrust Antivirus for the Gateway r7.1
Computer Associates: eTrust EZ Antivirus 2005 (v6.2)
Computer Associates: eTrust EZ Antivirus 6.0.123
Computer Associates: eTrust EZ Antivirus 6.0.125
Computer Associates: eTrust EZ Antivirus 6.1
Computer Associates: eTrust EZ Antivirus 6.1.0.24
Computer Associates: eTrust EZ Antivirus 6.1.3.1
Computer Associates: eTrust EZ Antivirus 6.1.4.0
Computer Associates: eTrust EZ Antivirus 6.1.5.8
Computer Associates: eTrust EZ Antivirus 6.1.7.0
Computer Associates: eTrust EZ Antivirus 6.2
Computer Associates: eTrust EZ Antivirus 6.2.0.28
Computer Associates: eTrust EZ Antivirus 6.3
Computer Associates: eTrust EZ Antivirus 6.4
Computer Associates: eTrust EZ Antivirus 6.4.0.4
Computer Associates: eTrust Intrusion Detection 2.0
Computer Associates: eTrust Intrusion Detection 2.0 SP1
Computer Associates: eTrust Intrusion Detection 3.0
Computer Associates: eTrust Intrusion Detection 3.0SP1
Computer Associates: eTrust Secure Content Manager 1.0
Computer Associates: eTrust Secure Content Manager 1.0 SP1
Computer Associates: eTrust Secure Content Manager 1.1
Computer Associates: EZ Armor 1.0.23
Computer Associates: EZ Armor 1.0.24
Computer Associates: EZ Armor 1.0.28
Computer Associates: EZ Armor 1.0.3
Computer Associates: EZ Armor 1.0.6
Computer Associates: EZ Armor 2.0
Computer Associates: EZ Armor 2.0.13
Computer Associates: EZ Armor 2.0.6
Computer Associates: EZ Armor 2.3
Computer Associates: EZ Armor 2.4
Computer Associates: EZ Armor 2.4.4
Computer Associates: EZ Armor 3.0.0.13
Computer Associates: EZ Armor 3.0.0.16
Computer Associates: EZ Armor 3.1
Computer Associates: EZ Armor 3.1.0
Computer Associates: EZ Armor 3.2
Computer Associates: InoculateIT 6.0
Computer Associates: Vet Antivirus 10.66
Zone Labs: ZoneAlarm Antivirus 5.0
Zone Labs: ZoneAlarm Antivirus 5.1
Zone Labs: ZoneAlarm Antivirus 5.5
Zone Labs: ZoneAlarm Security Suite 5.0
Zone Labs: ZoneAlarm Security Suite 5.1
Zone Labs: ZoneAlarm Security Suite 5.5

Back to top

References

Mitre CVE: CAN-2005-1693

Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All
 
 
Page Tools