PDA

Visualizza versione completa : CA Multiple Products Vet Antivirus Engine Buffer Overflow


Giorgius
26-05-2005, 12.47.33
Alex Wheeler has reported a vulnerability in various Computer Associates products, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an integer overflow in the Vet Antivirus Engine (VetE.dll) when analysing OLE streams. This can be exploited to cause a heap-based buffer overflow via e.g. a specially crafted Microsoft Office document...

Leggi:
http://secunia.com/advisories/15470/