PT-2005-1992 · Computer Associates · Etrust Intrusion Detection

Published

2005-04-05

·

Updated

2021-04-09

·

CVE-2005-0968

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Computer Associates (CA) eTrust Intrusion Detection version 3.0
Description The issue allows remote attackers to cause a denial of service by sending large size values that are not properly validated before calling the CPImportKey function in the Crypto API.
Recommendations For Computer Associates (CA) eTrust Intrusion Detection version 3.0, consider restricting access to the Crypto API until a patch is available. As a temporary workaround, avoid using the CPImportKey function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0968

Affected Products

Etrust Intrusion Detection