Title: CA eTrust Intrusion Detection SW3eng.exe Key Length Value Remote DoS
Info
Disclosure
Feb 27, 2007
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
CA eTrust Intrusion Detection contain a flaw that may allow a remote denial of service. The issue is due to the application failing to properly validate key length values during authentication and is triggered when a remote attacker sends a specially crafted packet containing a long key length value to the remote administration port (9191/TCP). This causes a heap-based buffer overflow in SW3eng.exe in the eID Engine, resulting in loss of availability for the service.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Private
Disclosure:
OSVDB Verified,
Vendor Verified
OSVDB:
Security Software
Solution
CA has released patches to address this issue. Additionally, it is possible to correct the flaw by implementing the following workaround(s):
Ensure only authorized hosts are permitted to connect to the Engine service port, 9191 by default, on the host running eTrust Intrusion Detection.