← Vulnerability feed

Vulnerability record · CVE-2005-0581 · published 2 May 2005

CVE-2005-0581: CA License Client/Server buffer overflows allow remote code execution

Broadcom · License Software

CA License Client and Server 0.1.0.15 contains multiple buffer overflows reachable through crafted GCR, GETCONFIG, and malformed request packets. Long fields such as Checksum items, IP address, hostname, netmask, or trailing parameters overflow fixed buffers and can lead to arbitrary code execution. The flaw matters because the affected component is a licensing service that may run with elevated privileges on managed hosts.

4.6 CVSS 2.0 Medium EPSS 46% · top 1.2%
4.6CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code via (1) certain long fields in the Checksum item in a GCR request, (2) a long IP address, hostname, or netmask values in a GCR request, (3) a long last parameter in a GETCONFIG packet, or (4) long values in a request with an invalid format.

AV:L/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityMultiple remotely reachable buffer overflows with potential code execution and a very high EPSS percentile outweigh the medium CVSS 2.0 score and lack of known exploitation.

What it is

CA License Client and Server 0.1.0.15 contains multiple buffer overflows reachable through crafted GCR, GETCONFIG, and malformed request packets. Long fields such as Checksum items, IP address, hostname, netmask, or trailing parameters overflow fixed buffers and can lead to arbitrary code execution. The flaw matters because the affected component is a licensing service that may run with elevated privileges on managed hosts.

Impact

A remote attacker can corrupt memory in the license service and potentially execute arbitrary code in its security context. Successful exploitation could give full control of the service process and, depending on its privileges, the underlying host.

Attack surface

The vulnerable code parses network requests to the CA License Client and Server, so the attack is reached over the network via crafted GCR, GETCONFIG, or malformed packets. The NVD CVSS vector is AV:L, which conflicts with the description's remote framing; no authentication or user interaction requirement is stated in the record.

Exploitation

The record shows no CISA KEV listing and no public exploit or ransomware association. EPSS is high at 0.46344 (98.762 percentile), indicating elevated predicted exploitation activity, but the references are vendor advisories and patch notices only.

What to do

  • Apply the vendor patch referenced in the CA security notice and iDefense advisories.
  • Restrict network access to the CA License Client and Server ports to trusted management hosts only.
  • If the license service is not required, disable or uninstall it on affected systems.
  • Run the license service with the least privileges necessary and isolate it from sensitive networks.
  • Monitor vendor support channels for updated builds of License Client and Server beyond 0.1.0.15.

Detection

  • Inspect network traffic to the license service for oversized or malformed GCR, GETCONFIG, and invalid-format requests.
  • Alert on crashes, restarts, or abnormal process behavior of the CA License Client and Server service.
  • Review host logs for unexpected child processes or command execution originating from the license service process.
  • Use IDS/IPS signatures for long Checksum, IP address, hostname, netmask, or trailing parameter values in license protocol packets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0581 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-0581), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.