Vulnerability Name: | CVE-2007-1005 (CCN-32718) | ||||||||
Assigned: | 2007-02-27 | ||||||||
Published: | 2007-02-27 | ||||||||
Updated: | 2021-04-09 | ||||||||
Summary: | Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp). | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1005 Source: IDEFENSE Type: Patch, Vendor Advisory 20070227 Computer Associates eTrust Intrusion Detection Denial of Service Vulnerability Source: CCN Type: SA24309 CA eTrust Intrusion Detection Key Length Value Denial of Service Source: SECUNIA Type: Patch, Vendor Advisory 24309 Source: CCN Type: SECTRACK ID: 1017706 CA eTrust Intrusion Detection Administration Interface Lets Remote Users Deny Service Source: CCN Type: CA SupportConnect Web site Security Notice for eTrust Intrusion Detection Source: CONFIRM Type: Patch, Vendor Advisory http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp Source: OSVDB Type: UNKNOWN 32290 Source: CCN Type: OSVDB ID: 32290 CA eTrust Intrusion Detection SW3eng.exe Key Length Value Remote DoS Source: BUGTRAQ Type: UNKNOWN 20070228 [CAID 35112]: CA eTrust Intrusion Detection Denial of Service Vulnerability Source: BID Type: Patch 22743 Source: CCN Type: BID-22743 CA eTrust Intrusion Detection System Key Exchange Remote Denial of Service Vulnerability Source: SECTRACK Type: UNKNOWN 1017706 Source: VUPEN Type: UNKNOWN ADV-2007-0776 Source: XF Type: UNKNOWN ca-etrust-key-dos(32718) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 02.27.07 Computer Associates eTrust Intrusion Detection Denial of Service Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |