HIGH · 9.3

CVE-2007-0060

Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in...

Vulnerability Description

Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
BroadcomAdvantage Data Transport3.0
BroadcomBrightstor Portal11.1
BroadcomBrightstor San Manager11.1
BroadcomCleverpath Aion10.0
BroadcomCleverpath Ecm3.5
BroadcomCleverpath Olap5.1
BroadcomCleverpath Predictive Analysis Server2.0
BroadcomEtrust Admin8.0
BroadcomUnicenter Application Performance Monitor3.0
BroadcomUnicenter Asset Management3.1
BroadcomUnicenter Data Transport Option2.0
BroadcomUnicenter Jasmine3.0
BroadcomUnicenter Network And Systems Management3.0
BroadcomUnicenter Nsm Wireless Network Management Option3.0
BroadcomUnicenter Remote Control6.0
BroadcomUnicenter Service Level Management3.0
BroadcomUnicenter Software Delivery3.0
BroadcomUnicenter Tng2.1
CaEtrust Admin2.1
CaUnicenter Asset Management4.0

References

FAQ

What is CVE-2007-0060?

CVE-2007-0060 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in...

How severe is CVE-2007-0060?

CVE-2007-0060 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-0060?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Advantage Data Transport, Broadcom Brightstor Portal, Broadcom Brightstor San Manager, Broadcom Cleverpath Aion, Broadcom Cleverpath Ecm.