Computer Associates Host-Based Intrusion Prevention System Remote Denial Of Service Vulnerability
BID:36078
Info
Computer Associates Host-Based Intrusion Prevention System Remote Denial Of Service Vulnerability
| Bugtraq ID: | 36078 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-2740 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2009 12:00AM |
| Updated: | Aug 21 2009 03:54PM |
| Credit: | iViZ Security Research Team |
| Vulnerable: |
Computer Associates Host-Based Intrusion Prevention System 8.1 |
| Not Vulnerable: |
Computer Associates Host-Based Intrusion Prevention System 8.1 CF 1 |
Discussion
Computer Associates Host-Based Intrusion Prevention System Remote Denial Of Service Vulnerability
Computer Associates Host-Based Intrusion Prevention System is affected by a denial-of-service vulnerability because the application mishandles malformed user-supplied input.
A remote attacker may exploit this issue to cause denial-of-service conditions.
Host-Based Intrusion Prevention System 8.1 is affected by this issue; other versions may also be vulnerable.
Computer Associates Host-Based Intrusion Prevention System is affected by a denial-of-service vulnerability because the application mishandles malformed user-supplied input.
A remote attacker may exploit this issue to cause denial-of-service conditions.
Host-Based Intrusion Prevention System 8.1 is affected by this issue; other versions may also be vulnerable.
Exploit / POC
Computer Associates Host-Based Intrusion Prevention System Remote Denial Of Service Vulnerability
Attackers can use readily available network utilities to exploit this issue.
Attackers can use readily available network utilities to exploit this issue.
Solution / Fix
Computer Associates Host-Based Intrusion Prevention System Remote Denial Of Service Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
References
Computer Associates Host-Based Intrusion Prevention System Remote Denial Of Service Vulnerability
References:
References:
- CA HIPS Agent Remote Kernel Vulnerability (iViZ )
- Host-Based Intrusion Prevention System Homepage (Computer Associates)
- CA20090818-01: Security Notice for CA Host-Based Intrusion Prevention System (Computer Associates)