>> CA Products Scan Job Description Field Handling Local Format String Vulnerability
Title : CA Products Scan Job Description Field Handling Local Format String Vulnerability VUPEN ID : VUPEN/ADV-2006-2565 CVE ID : CVE-2006-3223
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-06-27
Technical Description
A vulnerability has been identified in various Computer Associates products, which could be exploited by local attackers to obtain elevated privileges or cause a denial of service. This flaw is due to a format string error in the GUI when processing a scan job containing a malformed description field, which could be exploited by a malicious user to crash a vulnerable application or execute arbitrary commands via a specially crafted scan job.