HIGH · 9.3

CVE-2007-2864

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large inv...

Vulnerability Description

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
BroadcomAnti-Virus For The Enterprise8
BroadcomBrightstor Arcserve Backup9.01
BroadcomCommon Services1.0
BroadcomEtrust Antivirus8.0
BroadcomEtrust Antivirus Gateway7.1
BroadcomEtrust Antivirus SdkAll versions
BroadcomEtrust Ez Antivirus6.1
BroadcomEtrust Ez Armor1.0
BroadcomIntegrated Threat Management8.0
BroadcomInternet Security Suite1.0
BroadcomUnicenter Network And Systems Management3.0
CaEtrust Secure Content Manager8.0
CaProtection Suitesr2

References

FAQ

What is CVE-2007-2864?

CVE-2007-2864 is a vulnerability with a CVSS score of 9.3 (HIGH). Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large inv...

How severe is CVE-2007-2864?

CVE-2007-2864 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2864?

Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Anti-Virus For The Enterprise, Broadcom Brightstor Arcserve Backup, Broadcom Common Services, Broadcom Etrust Antivirus, Broadcom Etrust Antivirus Gateway.