CVE-2007-2864

Severity

93%

Complexity

86%

Confidentiality

165%

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

CVSS 2.0 Base Score 9.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).

Overview

Type

Computer Associates

First reported 17 years ago

2007-06-06 21:30:00

Last updated 6 years ago

2018-10-16 16:45:00

Affected Software

Computer Associates Anti-Virus for the Enterprise r8

8

Computer Associates BrightStor ARCserve Backup 9.01

9.01

Computer Associates BrightStor ARCServe Backup 10.5

10.5

Computer Associates BrightStor ARCserve Backup 11

11

Computer Associates BrightStor ARCserve Backup 11.1

11.1

Computer Associates BrightStor ARCserve Backup 11.5

11.5

Computer Associates Common Services 1.0

1.0

Computer Associates Common Services 1.1

1.1

Computer Associates Common Services 2.0

2.0

Computer Associates Common Services 2.1

2.1

Computer Associates Common Services 2.2

2.2

Computer Associates Common Services 3.0

3.0

Computer Associates eTrust Antivirus 8.0

8.0

Computer Associates etrust Antivirus 2007

8.1

Computer Associates etrust Antivirus Gateway 7.1

7.1

Computer Associates eTrust Anti-Virus SDK

Computer Associates eTrust EZ Antivirus 6.1

6.1

Computer Associates eTrust EZ Antivirus 7.0

7.0

Computer Associates eTrust EZ Armor 1.0

1.0

Computer Associates eTrust EZ Armor 2.0

2.0

Computer Associates eTrust EZ Armor 3.0

3.0

Computer Associates eTrust EZ Armor 3.1

3.1

Computer Associates eTrust Secure Content Manager 8.0

8.0

Computer Associates Integrated Threat Management 8.0

8.0

Computer Associates Internet Security Suite 1.0

1.0

Computer Associates Internet Security Suite 2.0

2.0

Computer Associates Internet Security Suite 2007

3.0

Computer Associates Unicenter Network and Systems Management 3.0

3.0

Computer Associates Unicenter Network and Systems Management 3.1

3.1

Computer Associates Unicenter Network and Systems Management 11

11

Computer Associates Unicenter Network and Systems Management 11.1

11.1

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.