CVE-2007-1005
Last modified
CVE-2007-1005 is a vulnerability of currently unknown severity. Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).. EPSS estimates a 6.70% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Broadcom | Etrust Intrusion Detection | 3.0 | — |
| Ca | Etrust Intrusion Detection | 2.0 | Sp1 |
| Ca | Etrust Intrusion Detection | 3.0 | Sp1 |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=484Patch, Vendor Advisory
- http://secunia.com/advisories/24309Patch, Vendor Advisory
- http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.aspPatch, Vendor Advisory
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=484Patch, Vendor Advisory
- http://secunia.com/advisories/24309Patch, Vendor Advisory
- http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.aspPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1005?
How severe is CVE-2007-1005?
How do I fix CVE-2007-1005?
Are you affected by CVE-2007-1005?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
