CVE-2005-0581 EXPLOIT
4.6
MEDIUM · CVSS 2.0 · EPSS 46.3% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.
Scoring
| CVSS | 4.6 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 46.34% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| broadcom | license software |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CA BrightStor ARCserve License Service - 'GCR NETWORK' Remote Buffer Overflow (Metasploit) | 2010-11-03 |
| exploit-db | Computer Associates License Client - GETCONFIG Overflow (Metasploit) | 2010-09-20 |
| exploit-db | Computer Associates License Server - GETCONFIG Overflow (Metasploit) | 2010-09-20 |
| exploit-db | CA License Server - 'GETCONFIG' Remote Buffer Overflow | 2005-03-06 |
References
- http://marc.info/?l=bugtraq&m=110979326828704&w=2
- http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp
- http://www.idefense.com/application/poi/display?id=210&type=vulnerabilities
- http://www.idefense.com/application/poi/display?id=213&type=vulnerabilities
- http://www.idefense.com/application/poi/display?id=214&type=vulnerabilities
- http://www.idefense.com/application/poi/display?id=215&type=vulnerabilities
- http://marc.info/?l=bugtraq&m=110979326828704&w=2
- http://supportconnectw.ca.com/public/ca_common_docs/security_notice.asp
- http://www.idefense.com/application/poi/display?id=210&type=vulnerabilities
- http://www.idefense.com/application/poi/display?id=213&type=vulnerabilities
- http://www.idefense.com/application/poi/display?id=214&type=vulnerabilities
- http://www.idefense.com/application/poi/display?id=215&type=vulnerabilities
→ the Explorer · watch your stack · NVD