
Yes it DoS, says FrSIRT
By Joris Evers
Published: 26 January 2006 08:50 GMT
A security vulnerability in CA's iTechnology iGateway service could put systems running the software at risk of serious attacks, experts have warned.
A remote attacker could gain complete control over systems on Windows platforms, and other platforms may allow for a denial of service attack, according to an advisory posted on Tuesday by security intelligence company the French Security Incident Response Team (FrSIRT). The FrSIRT rates the issue "critical".
The iTechnology iGateway is part of various CA products, including BrightStor back-up, eTrust security and Unicenter management software.
A heap-overflow vulnerability exists because the software fails to perform boundary checks before copying user-supplied data into specific process buffers, according to an advisory on Symantec's DeepSight intelligence service.
CA has published a security advisory along with fixes for its products.
Joris Evers writes for CNET News.com
Manage vulnerability assessments, penetration testing and compliance programs. Experience with threat and vulnerability management systems (Qualys, ...
Basic awareness of computer based vulnerability analysis testing. Moderate awareness of computer based vulnerability analysis testing. Furthermore, ...
Perform daily and monthly proactive checks as per customer requirements ? Manage calls to achieve SLA's, ensure that customer feedback during the ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business
Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business