>> Computer Associates Products DM Primer Denial of Service Vulnerabilities
Title : Computer Associates Products DM Primer Denial of Service Vulnerabilities VUPEN ID : VUPEN/ADV-2006-0236 CVE ID : CVE-2006-0306 - CVE-2006-0307
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-01-17
Technical Description
Two vulnerabilities were identified in various Computer Associates products, which could be exploited by remote attackers to cause a denial of service.
The first issue is due to an errror in the DM Primer part of the DM Deployment Common Component that does not properly handle unrecognized network messages, which could be exploited by attackers to cause high CPU utilization and excessive growth of the DM Primer log file.
The second flaw is due to an error in the way the DM Primer handles receipt of large rogue network messages, which could be exploited by remote attackers to cause the service to become unresponsive.