Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/0776 | vdb entry |
http://www.securityfocus.com/bid/22743 | patch vdb entry |
http://www.osvdb.org/32290 | vdb entry |
http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp | patch vendor advisory |
http://secunia.com/advisories/24309 | patch vendor advisory third party advisory |
http://www.securitytracker.com/id?1017706 | vdb entry |
http://www.securityfocus.com/archive/1/461567/100/100/threaded | mailing list |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=484 | patch vendor advisory third party advisory |