Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.

Project Subscriptions

Vendors Products
Broadcom Subscribe
Brightstor Arcserve Backup Subscribe
Brightstor Arcserve Backup Laptops Desktops Subscribe
Brightstor Portal Subscribe
Brightstor Process Automation Manager Subscribe
Brightstor San Manager Subscribe
Brightstor Storage Resource Manager Subscribe
Etrust Admin Subscribe
Etrust Audit Aries Subscribe
Etrust Audit Irecorder Subscribe
Etrust Identity Minder Subscribe
Etrust Integrated Threat Management Subscribe
Itechnology Igateway Subscribe
Unicenter Asset Portfolio Management Subscribe
Unicenter Autosys Jm Subscribe
Unicenter Service Delivery Subscribe
Unicenter Service Desk Subscribe
Unicenter Service Desk Knowledge Tools Subscribe
Unicenter Service Fulfillment Subscribe
Unicenter Service Metric Analysis Subscribe
Brightstor Arcserve Backup Subscribe
Brightstor Enterprise Backup Subscribe
Etrust Audit Aries Subscribe
Etrust Directory Subscribe
Etrust Secure Content Manager Subscribe
Unicenter Application Performance Monitor Subscribe
Unicenter Application Server Managment Subscribe
Unicenter Ca Web Services Distributed Management Subscribe
Unicenter Exchange Management Console Subscribe
Unicenter Management Subscribe
Unicenter Service Catalog Fulfillment Accounting Subscribe
Unicenter Service Fulfillment Subscribe
Unicenter Service Level Management Subscribe
Unicenter Web Server Management Subscribe
Unicenter Web Services Distributed Management Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T23:17:23.637Z

Reserved: 2005-11-18T05:00:00.000Z

Link: CVE-2005-3653

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2005-12-31T05:00:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2005-3653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses