Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 04-07-2005, 09:33 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Remote exploitation of a buffer overflow vulnerability in Computer Associates eTrust Intrusion Detection System can allow remote attackers to cause a denial of service condition.

The vulnerability specifically exists due to insufficient checking on values passed to Microsoft's Crypto API function CPImportKey. The CPImportKey function determines certain buffer allocation sizes from data supplied in the data blob passed to CPImportKey and may be manipulated to cause the allocation of large buffers if wrapper functions do not validate the data passed to the Crypto API before calling CPImportKey. In cases which CPImportKey receives a size value which exceeds the mapped memory size, an exception is generated and the memory is never freed.

This condition is met in the design of Computer Associates eTrust Intrusion Detection System and a specially crafted packet may exhaust all available memory resources, resulting in a denial of service.

III. ANALYSIS

Exploitation may allow remote attackers to cause the intrusion detection functionality of your network to fail, leading to undetected further exploitation of other machines on the network. Simple manipulation of fields in the header of normal remote administration traffic is all that is required to exploit this vulnerability. It should also be noted that other applications implementing similar Microsoft Crypto API functionality may be exploited in the same fashion.

IV. DETECTION

Computer Associates eTrust Intrusion Detection System 3.0 has been confirmed vulnerable.

V. WORKAROUND

Employ firewalls, access control lists or other TCP/UDP restriction mechanism to limit access to the administration port. In addition, the use of multiple intrusion detection products is recommended for sensitive networks.

VI. VENDOR RESPONSE

"Computer Associates has created a workaround that prevents this component issue from being exploited, by validating the key received from the "Viewer", and dropping the connection if not valid. This update to eTrust Intrusion Detection is available only for versions 3.0 and 3.0 SP1, at the following links."

For eTrust Intrusion Detection 3.0 customers, please go to:
QO66181 (r3.0)
http://supportconnectw.ca.com/premium/etrust/
etrust_intrusion/downloads/eid-solpatch_r30.asp#rel30

For eTrust Intrusion Detection 3.0 SP1 customers, please go to: QO66178 (r3.0 sp1)
http://supportconnectw.ca.com/premium/etrust/
etrust_intrusion/downloads/eid-solpatch_r30.asp#rel30sp1
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojandownloader And Unremovable Files- Woes Me ibrbrt Spyware / Virus Removal 9 06-18-2005 11:28 AM
Multiply Vulnerabilities With Computer Associates Mobo Security Alerts and vulnerabilities 0 03-06-2005 07:12 PM
E-trust ( Computer Associates) Mobo Software Update Alerts 0 11-16-2004 08:33 PM



All times are GMT -5. The time now is 05:59 PM.


Firefox 2