Back to search
CVE-2011-2667
Published: Jul 28, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.zerodayinitiative.com/advisories/ZDI-11-237/
x_refsource_MISC
20110720 CA20110720-01: Security Notice for CA Gateway Security and Total Defense
mailing-list
x_refsource_BUGTRAQ
1025812
vdb-entry
x_refsource_SECTRACK
8316
third-party-advisory
x_refsource_SREASON
20110720 ZDI-11-237: CA Total Defense Suite Gateway Security Malformed HTTP Packet Remote Code Execution Vulnerability
mailing-list
x_refsource_BUGTRAQ
48813
vdb-entry
x_refsource_BID
totaldefense-gateway-url-code-execution(68736)
vdb-entry
x_refsource_XF
1025813
vdb-entry
x_refsource_SECTRACK
45332
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now