CA exposure provokes disclosure debate

Cath Everett · Network Security · 2005

The discovery of multiple serious vulnerabilities in Computer Associates' enterprise license management software has re-ignited the debate over the ethics of disclosure. The holes, which were made public by security companies, eEye Digital Security and iDefense, at the start of March, are found in versions 1.53 to 1.61.8 of CA's License Client and Server applications that run on most widely available operating systems, ranging from Windows to Unix. This software enables customers to register, manage and track their licenses over the network and is installed by default in most of the vendor's products. While the server element is generally disabled, the same is not true of the client portion, so as Firas Raouf, chief operating officer of eEye, points out: “It's a big deal from an enterprise standpoint.”

Read the paper · More papers on PaperTik