• Home
  • Et Cetera

Infosecurity.US

Computer Associates Plugs Critical Holes In Multiple Software Releases

By Marc Handelman on October 16th, 2009

CA Logo

In patching news,  the remediation of multiple, and exploitable, flaws in several of  Islandia, New York based Computer Associates, Inc.’s (NasdaqGS: CA) software product lines has been announced. Ranging from Internet Security Suite, Common Services (CCS), eTrust Intrusion Detection, Network and Systems Management (NSM), Protection Suites,Gateway Security, ARCserve Backup, and last but certainly not least, Secure Content Manager and Threat Manager for the Enterprise. The full text release of the announcement appears after the jump.

CA20091008-01: Security Notice for CA Anti-Virus Engine

CA’s support is alerting customers to multiple security risks associated with CA Anti-Virus Engine. Vulnerabilities exist in the arclib component that can allow a remote attacker to cause a denial of service, or to cause heap corruption and potentially further compromise a system. CA has issued fixes to address the vulnerabilities. The first vulnerability, CVE-2009-3587, is due to improper handling of a specially crafted RAR archive file by the CA Anti-Virus engine arclib component. An attacker can create a malformed RAR archive file that results in heap corruption and allows the attacker to cause a denial of service or possibly further compromise the system. The second vulnerability, CVE-2009-3588, is due to improper handling of a specially crafted RAR archive file by the CA Anti-Virus engine arclib component. An attacker can create a malformed RAR archive file that results in stack corruption and allows the attacker to cause a denial of service.

Risk Rating

Medium

Platform

Windows
UNIX
Linux
Solaris
Mac OS X
Netware

Affected Products

CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1
CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8
CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) r8.1
CA Anti-Virus 2007 (v8)
CA Anti-Virus 2008
CA Anti-Virus 2009
CA Anti-Virus Plus 2009
eTrust EZ Antivirus r7.1
CA Internet Security Suite 2007 (v3)
CA Internet Security Suite 2008
CA Internet Security Suite Plus 2008
CA Internet Security Suite Plus 2009
CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) r8
CA Threat Manager for the Enterprise (formerly eTrust Integrated Threat Management) 8.1
CA Threat Manager Total Defense
CA Gateway Security r8.1
CA Protection Suites r2
CA Protection Suites r3
CA Protection Suites r3.1
CA Secure Content Manager (formerly eTrust Secure Content Manager) 1.1
CA Secure Content Manager (formerly eTrust Secure Content Manager) 8.0
CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r3.0
CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r3.1
CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r11
CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r11.1
CA ARCserve Backup r11.5 on Windows
CA ARCserve Backup r12 on Windows
CA ARCserve Backup r12.0 SP1 on Windows
CA ARCserve Backup r12.0 SP 2 on Windows
CA ARCserve Backup r12.5 on Windows
CA ARCserve Backup r11.1 Linux
CA ARCserve Backup r11.5 Linux
CA ARCserve for Windows Client Agent
CA ARCserve for Windows Server component
CA eTrust Intrusion Detection 2.0 SP1
CA eTrust Intrusion Detection 3.0
CA eTrust Intrusion Detection 3.0 SP1
CA Common Services (CCS) r3.1
CA Common Services (CCS) r11
CA Common Services (CCS) r11.1
CA Anti-Virus SDK (formerly eTrust Anti-Virus SDK)
CA Anti-Virus Gateway (formerly eTrust Antivirus Gateway) 7.1

Non-Affected Products

CA Anti-Virus engine with arclib version 8.1.4.0 or later installed

How to determine if the installation is affected

For products on Windows:

  1. Using Windows Explorer, locate the file “arclib.dll”. By default, the file is located in the “C:\Program Files\CA\SharedComponents\ScanEngine” directory (*).
  2. Right click on the file and select Properties.
  3. Select the Version tab.
  4. If the file version is earlier than indicated below, the installation is vulnerable.
File Name File Version
arclib.dll 8.1.4.0

*For eTrust Intrusion Detection 2.0, the file is located in “Program Files\eTrust\Intrusion Detection\Common”, and for eTrust Intrusion Detection 3.0 and 3.0 sp1, the file is located in “Program Files\CA\Intrusion Detection\Common”.

For CA Anti-Virus r8.1 on non-Windows platforms:

Use the compver utility provided on the CD to determine the version of Arclib. If the version is less than 8.1.4.0, the installation is vulnerable.

Example compver utility output:

                                       ------------------------------------------------
                                       COMPONENT NAME VERSION
                                       ------------------------------------------------
                                       eTrust Antivirus Arclib Archive Library 8.1.4.0
                                       ... (followed by other components)

For reference, the following are file names for arclib on non-Windows operating systems:

Operating System File name
Solaris libarclib.so
Linux libarclib.so
Mac OS X arclib.bundle

Solution

CA released arclib 8.1.4.0 on August 12 2009. If your product is configured for automatic updates, you should already be protected, and you need to take no action. If your product is not configured for automatic updates, then you simply need to run the update utility included with your product.

CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r3.0: apply fix # RO11964.

CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r3.1: apply fix # RO11964.

CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r11: apply fix # RO11964.

CA Network and Systems Management (NSM) (formerly Unicenter Network and Systems Management) r11.1: apply fix # RO11964.

CA Common Services (CCS) r3.1: apply fix # RO11954.

CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 32bit: apply fix # RO10663.

CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 IA64: apply fix # RO10664.

CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 AMD64: apply fix # RO10665.

CA Secure Content Manager (formerly eTrust Secure Content Manager) r1.1: apply fix # RO10999.

CA Secure Content Manager (formerly eTrust Secure Content Manager) r8.0: apply fix # RO10999.

CA Anti-Virus Gateway (formerly eTrust Antivirus Gateway) 7.1: apply fix # RO11000.

CA Gateway Security r8.1: RO10999.

CA ARCserve for Windows Server component installed on a 64 bit machine: apply fixes # RO10663 and RO10664 (IA64) or RO10665 (AMD64).

CA ARCserve for Windows Server component installed on a 32 bit machine: apply fix # RO10663.

CA ARCserve for Windows Client Agent installed on a 64 bit machine: apply fix # RO10664 (IA64) or RO10665 (AMD64).

CA ARCserve for Windows Client Agent installed on a 32 bit machine: apply fix # RO10663.

CA ARCserve for Linux Server r11.5: apply fix # RO10729.

CA ARCserve for Linux:

  1. Download RO10729.tar.Z from RO10729 into a temporary location /tmp/RO10729
  2. Uncompress and untar RO10729.tar.Z as follows:
    uncompress RO10729.tar.Z
    tar -xvf RO10729.tar

    The new “libarclib.so” will be extracted to /tmp/RO10729

  3. Change the directory to $CAIGLBL0000/ino/config as follows:
    cd $CAIGLBL0000/ino/config
  4. Rename “libarclib.so” to “libarclib.so.RO10729″ as follows:
    mv libarclib.so libarclib.so.RO10729
  5. Copy the new libarclib.so as follows:
    cp /tmp/RO10729/libarclib.so $CAIGLBL0000/ino/config/
  6. chmod +x $CAIGLBL0000/ino/config/libarclib.so
  7. Stop the common agent (caagent stop)
  8. Change the directory to ARCserve common agent directory (typically /opt/CA/BABcmagt)
    cd /opt/CA/BABcmagt

    Note: To find out the agent home directory run the following command:
    dirname ‘ls -l /usr/bin/caagent |cut -f2 -d”>”‘

  9. Save a copy of libarclib.so
    cp -p libarclib.so libarclib.so.RO10729
  10. Copy over the new libarclib.so as follows:
    cp $/tmp/RO10729/libarclib.so.
  11. Start the common agent (caagent start)
  12. Repeat steps (7-11) on all remote Linux client agents’ installations.
  13. rm -rf /tmp/RO10729

Workaround

Do not open email attachments or download files from untrusted sources.

References

CVE-2009-3587 – CA Anti-Virus RAR archive heap corruption

CVE-2009-3588 – CA Anti-Virus RAR archive stack corruption

Acknowledgement

CVE-2009-3587 – Thierry Zoller – G-SEC

CVE-2009-3588 – Thierry Zoller – G-SEC

Change History

Version 1.0: Initial Release
Version 1.1: Updated list of affected products; added workaround.

If additional information is required, please contact CA Support at https://support.ca.com.

If you discover a vulnerability in CA products, please report your findings to the CA Product Vulnerability Response Team.

Categories: Infosecurity
Tags: Computer Associates, Features, Software Patching

Related Headlines

    Related posts:

    1. Critical Security Software Flaws Rise, Users At Risk
    2. Oracle Enterprise Manager DB Grid Control Security Update
    3. AVG Anti-Virus Deletes Windows System File
    4. Redmond Releases AV Solution. Alert The Media.
    5. VMWare Releases Critical Security Patch – Fusion Now At 2.5

3 Responses to “Computer Associates Plugs Critical Holes In Multiple Software Releases”

  1. Ramon Spearman
    Oct 16th, 2009 at 11:57

    Computer Associates Plugs Critical Holes In Multiple Software Releases http://bit.ly/2ooSCX

  2. Awilda Batista
    Oct 16th, 2009 at 12:35

    Computer Associates Plugs Critical Holes In Multiple Software Releases http://bit.ly/2C8rlp

  3. firescience
    Oct 16th, 2009 at 22:45

    Computer Associates Plugs Critical Holes In Multiple Software Releases: In patching news, the remediation of mul.. http://bit.ly/2C8rlp

« Dilbert: The Project Timeline Wilkinson: Education »
  • Latest
  • Random
  • Bookmarks
  • Archives
  • Steve Benson: Persian Lights…
  • New, Pernicious BotNet Emerges
  • VMWare Announces ESX Console Security Update
  • Nick Anderson: Egg
  • Doppelgänger Infinitus
  • Robert Ariall: Iran For Cover
  • Data Leakage Wednesdays: Old Printer Vector
  • XKCD: Exoplanets
  • Apple Releases Magic Footpad, Raises Ante On Bipedal Computer Controls
  • Science Tuesday: Asteroidal Discoveries Mapped, 01980 – 02010
  • DNS Vulnerability Originally Discovered By SANS GSEC Student
  • XKCD: Idiocracy
  • GNUCITIZEN – Advanced Clickjacking Explained
  • Bad News For SATYAM – CEO Resigns After Admitting Fraud
  • Social Networking: How to Avoid The Digital Hangover
  • Rob Rogers: Once Upon A Time In China
  • USCERT Issues Cyber Security Alert: Windows AutoRun Risk
  • Mozilla Foundation Addresses Zero Day Flaw, Updates Firefox
  • Additional Details Revealed – Chinese Cyberattack On Google Deeper Than Originally Thought
  • WEBECON 101: Why Competition Is Good – Chrome vs. Firefox
  • Apple
  • BSD
  • Closson
  • Darknet
  • Debian
  • Finnigan
  • ha.ckers
  • Hoff
  • Insecure
  • Krebs
  • Layer8
  • MSRC
  • Network Security Blog
  • NSA SEL
  • openSUSE
  • RedHat
  • SANS
  • Schneier
  • Security Eunoia
  • Securosis
  • Shimel
  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
Subscribe

Featured Blog - Blogs.com SANS Security Reading Room KnotOriginal: fine art to hang on your body and walls Member - Security Bloggers Network

Dilbert

KnotOriginal

Featured Video

QOTD

RSS Security Bloggers Network

  • Two Wheel EV Recumbant: Zerotracer 2010/09/02 Davi Ottenheimer
  • Ben Franklin’s Endpoint Security Advice 2010/09/02 Jeff Hughes
  • Configuring Conditional SSH Connections 2010/09/02 Xavier
  • Truecrypt and USB drives 2010/09/02 always peace
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Andrew Hay
  • Safe Web Surfing Rule # 1: READ the URL 2010/09/02 Tom Kelchner
  • Heartland Set To Pay Discover $5M For 2008 Data Breach 2010/09/02 spinman
  • User’s Opinions on Malware Infections 2010/09/02 spinman
  • Acunetix Web Vulnerability Scanner 7 Released 2010/09/02 spinman
  • LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs 2010/09/02 Anton Chuvakin

RSS Cryptography

  • Monitor: Schrodinger's cat and mouse 2010/09/02
  • How to configure a Junos security device 2010/09/02
  • Net Effect: Hay-what? 2010/09/02
  • The Art of Proof 2010/09/02
  • Quantum crypto cracked, researchers say 2010/09/01

RSS SANS ISC

  • Microsoft EMETv2 released, (Thu, Sep 2nd) 2010/09/02
  • SDF, please!, (Thu, Sep 2nd) 2010/09/02
  • Month of Undisclosed 0-day Bugs, (Wed, Sep 1st) 2010/09/01
  • Microsoft issues updates to sysinternals ProcDump and Process Monitor: http://blogs.technet.com/b/sysinternals/archive/2010/08/30/updates-procdump-process-monitor-and-a-new-mark-s-blog-post.aspx, (Wed, Sep 1st) 2010/09/01
  • VMWARE releases 2 security advisories for ESX Service Console: http://lists.vmware.com/pipermail/security-announce/2010/000103.html and http://lists.vmware.com/pipermail/security-announce/2010/000104.html, (Wed, Sep 1st) 2010/09/01

RSS Oracle

  • Going to Oracle OpenWorld 2010? 2010/09/02
  • Automatic Time Zone support in Application Express 4.0 2010/09/02
  • EBS, Collaborate, Security, BPEL, OWB, Blog of Note, Hyperion, EPM, Burnout, WiFi 2010/09/02
  • Details of Tuxedo sessions at OOW 2010/09/02
  • JavaOne Preview on TechCast Live! (Tues., Sept. 7, 10am PT) 2010/09/02
  • links for 2010-09-02 2010/09/02
  • Join us for a Bersin & Associates Webcast - "Evolution of ERPs: Driving Business Value through Integrated Talent Management" 2010/09/02

RSS MySQL

  • Join MySQL at OSCON 2010/07/02
  • TechCast Live: Jono Bacon and Luke Kowalski on MySQL Community 2010/05/21
  • What's New in the MySQL Enterprise Spring 2010 Release? - Interview with Mark Matthews and Andy Bang 2010/05/17
  • Introduction to MySQL 5.5 2010/04/13
  • Why Should I Check Out a MySQL-Based Column Database ? 2010/02/12
  • A deep look at MySQL 5.5 partitioning enhancements 2009/12/24
  • Sun "Tech Days" Conference World Tour Kicks Off in Brazil 2009/12/07

RSS Linux

  • A Guide to Today's Top 10 Linux Distributions - NetworkWorld.com 2010/09/02
  • Embedded Linux Conference videos available - LWN.net 2010/09/02
  • Net Applications' iOS vs Linux Report Confuses Me - Muktware (blog) 2010/09/02
  • Cloudlinux Named Editor's Choice By Web Host Magazine & Buyer's Guide - PR Urgent 2010/09/02
  • Samsung's 3D TV remote let's you take the screen with you - Geek.com 2010/09/02

RSS MAC OSX

  • Samsung Reveals Half-Pint iPad, The Galaxy Tab 2010/09/02 Eli Milchman
  • Daily Deals: New nano, touch and Apple TV 2010/09/02 Ed Sutherland
  • iPhone 4 Coffee Table Gets You Better Reception Than iPod Table? 2010/09/02 Nicole Martinelli
  • Walkman Outsells iPods in Japan, Can Wristwatch Nano Change That? 2010/09/02 Nicole Martinelli
  • Amazon: Buy – Don’t Rent – 99-Cent Fox, ABC TV Episodes 2010/09/02 Ed Sutherland
  • Analyst: New Apple TV Rival for Cable’s Video-on-Demand 2010/09/02 Ed Sutherland
  • iTunes Ping And Facebook: What’s Going On? 2010/09/02 Giles Turnbull

RSS Microsoft

  • Update on Security Advisory 2269637 2010/08/31 MSRCTEAM
  • Microsoft Security Advisory 2269637 Released 2010/08/22 MSRCTEAM
  • August 2010 Webcast and QA 2010/08/12 MSRCTEAM
  • Update on the publicly disclosed Win32k.sys EoP Vulnerability 2010/08/10 MSRCTEAM
  • August 2010 Security Bulletin Release 2010/08/10 MSRCTEAM
  • August 2010 Bulletin Release Advance Notification 2010/08/05 MSRCTEAM
  • August 2010 Out-of-Band Security Release Webcast Q&A 2010/08/03 MSRCTEAM

RSS Network

  • How to get started with a blade system 2010/09/02
  • Opsview Community Edition review 2010/09/02
  • Cacti review 2010/09/02
  • Brocade adds 100G Ethernet to switch and router line 2010/09/02
  • Is Cisco making a play for Skype? 2010/08/31
  • Skype launches Skype Connect enterprise voice calling 2010/08/31
  • Sonos ZonePlayer S5 review 2010/08/25

Daily Posts

September 2010
S M T W T F S
« Aug    
 1234
567891011
12131415161718
19202122232425
2627282930  
Creative Commons License
The Infosecurity.US Blog is licensed under a Creative Commons Attribution-Share Alike 3.0 United States License.

Find the best blogs at Blogs.com.

Creative Commons Attribution-Share Alike 3.0 U.S. License ©2010 Infosecurity.US

Subscribe