CVE-2005-3653
Last modified
CVE-2005-3653 is a vulnerability of currently unknown severity. Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.. EPSS estimates a 18.64% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Broadcom | Brightstor Arcserve Backup | 9.01 | — |
| Broadcom | Brightstor Arcserve Backup | 11.1 | — |
| Broadcom | Brightstor Arcserve Backup | 11.5 | — |
| Broadcom | Brightstor Arcserve Backup Laptops Desktops | 11.0 | — |
| Broadcom | Brightstor Arcserve Backup Laptops Desktops | 11.1 | — |
| Broadcom | Brightstor Portal | 11.1 | — |
| Broadcom | Brightstor Process Automation Manager | 11.1 | — |
| Broadcom | Brightstor San Manager | 11.1 | — |
| Broadcom | Brightstor San Manager | 11.5 | — |
| Broadcom | Brightstor Storage Resource Manager | 6.3 | — |
| Broadcom | Brightstor Storage Resource Manager | 6.4 | — |
| Broadcom | Brightstor Storage Resource Manager | 11.1 | — |
| Broadcom | Brightstor Storage Resource Manager | 11.5 | — |
| Broadcom | Etrust Admin | 8.1 | — |
| Broadcom | Etrust Audit Aries | 8.0 | — |
| Broadcom | Etrust Audit Irecorder | 1.5 | Sp2 |
| Broadcom | Etrust Audit Irecorder | 8.0 | — |
| Broadcom | Etrust Identity Minder | 8.0 | — |
| Broadcom | Etrust Integrated Threat Management | 8.0 | — |
| Broadcom | Itechnology Igateway | <= 4.0.050615 | — |
| Broadcom | Unicenter Asset Portfolio Management | 11.0 | — |
| Broadcom | Unicenter Autosys Jm | 11.0 | — |
| Broadcom | Unicenter Service Delivery | 11.0 | — |
| Broadcom | Unicenter Service Desk | 11.0 | — |
| Broadcom | Unicenter Service Desk Knowledge Tools | 11.0 | — |
| Broadcom | Unicenter Service Fulfillment | 2.2 | — |
| Broadcom | Unicenter Service Metric Analysis | 11.0 | — |
| Ca | Brightstor Arcserve Backup | 11 | — |
| Ca | Brightstor Enterprise Backup | 10.0 | — |
| Ca | Brightstor Enterprise Backup | 10.5 | — |
| Ca | Etrust Audit Aries | 1.5 | Sp2 |
| Ca | Etrust Directory | 8.1_web_components | — |
| Ca | Etrust Secure Content Manager | 8.0 | — |
| Ca | Unicenter Application Performance Monitor | 11.0 | — |
| Ca | Unicenter Application Server Managment | 11.0 | — |
| Ca | Unicenter Ca Web Services Distributed Management | 11.0 | — |
| Ca | Unicenter Exchange Management Console | 11.0 | — |
| Ca | Unicenter Management | 3.5 | — |
| Ca | Unicenter Management | 11.0 | — |
| Ca | Unicenter Service Catalog Fulfillment Accounting | 11.0 | — |
| Ca | Unicenter Service Fulfillment | 11.0 | — |
| Ca | Unicenter Service Level Management | 11.0 | — |
| Ca | Unicenter Web Server Management | 11.0 | — |
| Ca | Unicenter Web Services Distributed Management | 11.0 | — |
References
- http://secunia.com/advisories/18591Patch, Vendor Advisory
- http://supportconnectw.ca.com/public/ca_common_docs/igatewaysecurity_notice.aspPatch, Vendor Advisory
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=376Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0311Vendor Advisory
- http://secunia.com/advisories/18591Patch, Vendor Advisory
- http://supportconnectw.ca.com/public/ca_common_docs/igatewaysecurity_notice.aspPatch, Vendor Advisory
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=376Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0311Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3653?
How severe is CVE-2005-3653?
How do I fix CVE-2005-3653?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3647Folder Guard allows local users to bypass protections by run…
- CVE-2005-3648Multiple SQL injection vulnerabilities in the get_record fun…
- CVE-2005-3649jumpto.php in Moodle 1.5.2 allows remote attackers to redire…
- CVE-2005-3650The CodeSupport.ocx ActiveX control, as used by Sony to unin…
- CVE-2005-3651Stack-based buffer overflow in the dissect_ospf_v3_address_p…
- CVE-2005-3652Heap-based buffer overflow in Citrix Program Neighborhood cl…
- CVE-2005-3654Blue Coat Systems Inc. WinProxy before 6.1a allows remote at…
- CVE-2005-3655Heap-based buffer overflow in Novell Open Enterprise Server …
- CVE-2005-3656Multiple format string vulnerabilities in logging functions …
- CVE-2005-3657The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Sec…
- CVE-2005-3658Multiple heap-based buffer overflows in EMC Legato NetWorker…
- CVE-2005-3659nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.…
Are you affected by CVE-2005-3653?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
