>> CA eTrust Intrusion Detection Authentication Key Handling Denial of Service Vulnerability
Title : CA eTrust Intrusion Detection Authentication Key Handling Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2007-0776 CVE ID : CVE-2007-1005
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-28
Technical Description
A vulnerability has been identified in CA eTrust Intrusion Detection, which could be exploited by remote attackers to cause a denial of service. This issue is due to an error in the Engine service that fails to properly validate the key length value during authentication, which could be exploited by attackers to cause a vulnerable application to unexpectedly terminate by sending a specially crafted request to port 9191/TCP.