The InformationWeek -- Blogs

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

CA Customers Newly Targeted


Posted by George Hulme, Mar 28, 2008 08:44 PM

While most software exploits target end users and end-point applications, this one is aiming squarely at corporate users.


Just last week researchers started warning about a single vulnerability that affects a large number of CA (the software vendor formally known as Computer Associates) products, from CA BrightStor ARCServe Backup through various Unicenter apps.

According to a security bulletin published by FrSIRT, the flaw in question is critical, and can lead to denial-of-service attacks and even the commandeering of the targeted system.

BTW – the error that makes all of this fun possible is (yet another) buffer overflow. (Maybe we should all start writing our representatives and demand that there be a federal "Developers: Check Your Inputs Day." It might help build some much needed awareness on a very old problem.)

This vulnerability is a big deal by itself, first because of the huge install-base of the affected products, and second because of the nature of these applications. Being able to compromise one of these systems in a corporation could make a quick stepping-stone to more crucial servers – especially considering how mushy-gushy most corporate network security is deep behind the DMZ.

What makes it more interesting, as Roger Thompson points out over at Exploit Prevention Labs is that a working attack exploit has been added to the NeoSploit attack framework.

CA has issued a patch.

« Energy Camp @ Interop: Calling All Interested Parties In IT Energy Savings | Main | Lockdown Tradeoffs »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. HPC Joins the Dummy Revolution?
  2. Detecting Scalability Problems With Intel Parallel Universe Portal
  3. Just Say No To SFAQL Parallelism


Join The InformationWeek Group On LinkedIn


                           


  1. Top Resources To Save Big On Cyber Monday
  2. AT&T, T-Mobile, Verizon All Offering Black Friday Sales
  3. Verizon Snags Samsung's Omnia II With WinMo 6.5
  4. Murdoch And Microsoft Redefine Search
  5. Thoughts On The Motorola Droid


  1. Feds Providing $80 Million For Health IT Training
  2. Amazon Boasts Record Kindle Sales
  3. Lenovo Buys Back Mobile Unit
  4. Ericsson To Buy Nortel GSM Unit For $70 Million
  5. Government CIOs Must Focus On Results, Not Data Centers
  6. Elastra Cloud Server Preps Apps For Azure, Amazon

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007