Description
The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs.
Affected products
- Broadcom / etrust_antivirus8.1 – 8.1
- Broadcom / etrust_antivirus8.2 – 8.2
- Broadcom / internet_security_suite3.0 – 3.0
References
- MISChttp://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=34870
- MISChttp://crm.my-etrust.com/CIDocument.asp?KDId=2651&GUID=9FD7E4F8362C4A168D88B4FFA34DCB4C
- MISChttp://www.securityfocus.com/archive/1/454420/100/0/threaded
- MISChttp://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=41
- MISChttp://www.osvdb.org/30845
- MISChttp://www.securityfocus.com/bid/21593
- MISChttp://securitytracker.com/id?1017382
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/30909
- VENDOR_ADVISORYhttp://secunia.com/advisories/23378
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2006/5010
- MISChttp://securitytracker.com/id?1017381