Icihttp.exe in CA Gateway Security for HTTP, as used in CA Gateway Security 8.1 before 8.1.0.69 and CA Total Defense r12, does not properly parse URLs, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and daemon crash) via a malformed request.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2011-07-28T22:00:00
Updated: 2024-08-06T23:08:23.762Z
Reserved: 2011-07-06T00:00:00
Link: CVE-2011-2667
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-07-28T22:55:02.390
Modified: 2024-11-21T01:28:43.423
Link: CVE-2011-2667
Redhat
No data.