← Vulnerability feed

Vulnerability record · CVE-2008-2541 · published 4 June 2008

CVE-2008-2541: Ca etrust secure content manager memory buffer overflow vulnerability

CCa · Etrust Secure Content Manager

Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.

10.0 CVSS 2.0 High EPSS 10% · top 4.5% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://dvlabs.tippingpoint.com/advisory/TPTI-08-05
http://secunia.com/advisories/30518 Vendor Advisory
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36408
http://www.securityfocus.com/archive/1/493082/100/0/threaded
http://www.securityfocus.com/archive/1/493084/100/0/threaded
http://www.securityfocus.com/archive/1/493087/100/0/threaded
http://www.securityfocus.com/archive/1/493124/100/0/threaded
http://www.securityfocus.com/bid/29528
http://www.securitytracker.com/id?1020167
http://www.vupen.com/english/advisories/2008/1741/references Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-08-035/
http://www.zerodayinitiative.com/advisories/ZDI-08-036
https://exchange.xforce.ibmcloud.com/vulnerabilities/42821
https://support.ca.com/irj/portal/anonymous/SolutionResults?aparNo=QO99987&os=NT&actionID=3 Patch
http://dvlabs.tippingpoint.com/advisory/TPTI-08-05
http://secunia.com/advisories/30518 Vendor Advisory
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=36408
http://www.securityfocus.com/archive/1/493082/100/0/threaded
http://www.securityfocus.com/archive/1/493084/100/0/threaded
http://www.securityfocus.com/archive/1/493087/100/0/threaded
http://www.securityfocus.com/archive/1/493124/100/0/threaded
http://www.securityfocus.com/bid/29528
http://www.securitytracker.com/id?1020167
http://www.vupen.com/english/advisories/2008/1741/references Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-08-035/
http://www.zerodayinitiative.com/advisories/ZDI-08-036
https://exchange.xforce.ibmcloud.com/vulnerabilities/42821
https://support.ca.com/irj/portal/anonymous/SolutionResults?aparNo=QO99987&os=NT&actionID=3 Patch

Track CVE-2008-2541 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0758Ca etrust secure content manager vulnerabilityThe eCS component (ECSQdmn.exe) in CA ETrust Secure Content Manager 8.0 and CA Gateway Security 8.1 allows remote attackers to cause a denial of serv…EPSS 8.2%10.0CVE-2007-3334Ca etrust secure content manager vulnerabilityMultiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Databa…EPSS 10%10.0CVE-2005-3653Broadcom brightstor arcserve backup memory buffer overflow vulnerabilityHeap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.0512…EPSS 19%10.0CVE-2005-1693Broadcom etrust antivirus vulnerabilityInteger overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for…EPSS 6.9%9.3CVE-2009-3587Broadcom anti-virus vulnerabilityUnspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 throug…EPSS 7.6%9.3CVE-2007-2864CA Anti-Virus engine stack buffer overflow via crafted CAB fileThe Anti-Virus engine in multiple CA (Computer Associates) products before content update 30.6 has a stack-based buffer overflow triggered by a large…EPSS 50%analysed7.5CVE-2004-0937Archive zip vulnerabilitySophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protecti…EPSS 15%7.5CVE-2004-0932McAfee Anti-Virus Engine DATS driver bypass via malformed compressed fileThe McAfee Anti-Virus Engine DATS drivers before 4398 (Oct 13 2004) and DATS Driver before 4397 (Oct 6 2004) fail to properly handle compressed files…EPSS 63%analysed

Source: NIST National Vulnerability Database (record CVE-2008-2541), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.