PT-2005-1992 · Computer Associates · Etrust Intrusion Detection

Publicado

2005-04-05

·

Atualizado

2021-04-09

·

CVE-2005-0968

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Computer Associates (CA) eTrust Intrusion Detection version 3.0
Description The issue allows remote attackers to cause a denial of service by sending large size values that are not properly validated before calling the CPImportKey function in the Crypto API.
Recommendations For Computer Associates (CA) eTrust Intrusion Detection version 3.0, consider restricting access to the Crypto API until a patch is available. As a temporary workaround, avoid using the CPImportKey function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0968

Produtos afetados

Etrust Intrusion Detection