You are here: silicon.com > Software > Security Strategy

Security Strategy

CA software poses "critical" security risk

Yes it DoS, says FrSIRT

Tags: dos, flaw, security, ca

By Joris Evers

Published: 26 January 2006 08:50 GMT

A security vulnerability in CA's iTechnology iGateway service could put systems running the software at risk of serious attacks, experts have warned.

A remote attacker could gain complete control over systems on Windows platforms, and other platforms may allow for a denial of service attack, according to an advisory posted on Tuesday by security intelligence company the French Security Incident Response Team (FrSIRT). The FrSIRT rates the issue "critical".

The iTechnology iGateway is part of various CA products, including BrightStor back-up, eTrust security and Unicenter management software.

A heap-overflow vulnerability exists because the software fails to perform boundary checks before copying user-supplied data into specific process buffers, according to an advisory on Symantec's DeepSight intelligence service.

CA has published a security advisory along with fixes for its products.

Joris Evers writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Security Consultants - Penetration Testing / Vulnerability Assessment

URGENT - PEN TESTER - WEB APPS (HOMEBASED / REMOTE) to start THIS MONDAY; Dureation 1 WEEK + EXTENSION (Cica 20 days) for an urgent security pen ...

Security Operations Centre Manager (SOC Manager), SC Security Cleared

Basic awareness of computer based vulnerability analysis testing. Moderate awareness of computer based vulnerability analysis testing. Furthermore, ...

Web Applications Vulnerability Tester

Title: Web Applications Vulnerability Tester / Penetration Tester Salary: market rates but probably 40k to 60k Company: online / ecommerce company ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: