CVE-2008-2541: Buffer Overflow
Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2541?
CVE-2008-2541 has been classified as critical due to the potential for remote code execution and denial of service.
How do I fix CVE-2008-2541?
To fix CVE-2008-2541, apply the latest patches provided by CA for eTrust Secure Content Manager 8.0.
What are the consequences of exploiting CVE-2008-2541?
Exploitation of CVE-2008-2541 can lead to arbitrary code execution or a denial of service condition on impacted systems.
Which software versions are affected by CVE-2008-2541?
CVE-2008-2541 affects CA eTrust Secure Content Manager version 8.0.
What components of eTrust Secure Content Manager are vulnerable in CVE-2008-2541?
The vulnerability in CVE-2008-2541 exists specifically in the HTTP Gateway Service, icihttp.exe.