CVE-2005-3653: Buffer Overflow
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3653?
CVE-2005-3653 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2005-3653?
To fix CVE-2005-3653, update to a version of iTechnology iGateway that is later than 4.0.051230.
What type of attack does CVE-2005-3653 enable?
CVE-2005-3653 enables remote attackers to execute arbitrary code through specially crafted HTTP requests.
Which products are affected by CVE-2005-3653?
CVE-2005-3653 affects various Computer Associates (CA) iTechnology products, particularly versions of iGateway prior to 4.0.051230.
Is there a workaround for CVE-2005-3653 if I cannot update?
As a workaround for CVE-2005-3653, consider restricting access to the iGateway service or implementing a firewall rule to block untrusted HTTP requests.