ISS RealSecure DHCP Signature Remote Denial Of Service Vulnerability
BID:4649
Info
ISS RealSecure DHCP Signature Remote Denial Of Service Vulnerability
| Bugtraq ID: | 4649 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2002 12:00AM |
| Updated: | Apr 30 2002 12:00AM |
| Credit: | Vulnerability announced by ISS X-Force. |
| Vulnerable: |
Internet Security Systems RealSecure Network Sensor 6.5 Internet Security Systems RealSecure Network Sensor 6.0 XPU 3.4 Internet Security Systems RealSecure Network Sensor 5.5.2 XPU 3.4 Internet Security Systems RealSecure Network Sensor 5.5.1 XPU 3.4 Internet Security Systems RealSecure Network Sensor 5.5 XPU 3.4 Internet Security Systems RealSecure Network Sensor 5.0 XPU 3.4 |
| Not Vulnerable: | |
Discussion
ISS RealSecure DHCP Signature Remote Denial Of Service Vulnerability
RealSecure is the commercial Intrusion Detection System (IDS) distributed and maintained by ISS.
RealSecure becomes unstable when processing some of the DHCP signatures packaged with the system. Due to the construction of the three DHCP signatures (DHCP_ACK - 7131, DHCP_Discover - 7132, and DHCP_Request - 7133), the RealSecure software may become unstable and crash. This is due to the software attempting to dereference a null pointer. By sending malicious DHCP traffic, it may be possible for a remote attacker to cause a denial of service.
If the sensor is disabled, further attacks may go unnoticed.
RealSecure is the commercial Intrusion Detection System (IDS) distributed and maintained by ISS.
RealSecure becomes unstable when processing some of the DHCP signatures packaged with the system. Due to the construction of the three DHCP signatures (DHCP_ACK - 7131, DHCP_Discover - 7132, and DHCP_Request - 7133), the RealSecure software may become unstable and crash. This is due to the software attempting to dereference a null pointer. By sending malicious DHCP traffic, it may be possible for a remote attacker to cause a denial of service.
If the sensor is disabled, further attacks may go unnoticed.
Exploit / POC
ISS RealSecure DHCP Signature Remote Denial Of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
ISS RealSecure DHCP Signature Remote Denial Of Service Vulnerability
Solution:
Fixes available:
Internet Security Systems RealSecure Network Sensor 5.0 XPU 3.4
Internet Security Systems RealSecure Network Sensor 5.5 XPU 3.4
Internet Security Systems RealSecure Network Sensor 5.5.1 XPU 3.4
Internet Security Systems RealSecure Network Sensor 5.5.2 XPU 3.4
Internet Security Systems RealSecure Network Sensor 6.0 XPU 3.4
Internet Security Systems RealSecure Network Sensor 6.5
Solution:
Fixes available:
Internet Security Systems RealSecure Network Sensor 5.0 XPU 3.4
-
Internet Security Systems RealSecure X-Press Update 4.3
http://www.iss.net/download/
Internet Security Systems RealSecure Network Sensor 5.5 XPU 3.4
-
Internet Security Systems RealSecure X-Press Update 4.3
http://www.iss.net/download/
Internet Security Systems RealSecure Network Sensor 5.5.1 XPU 3.4
-
Internet Security Systems RealSecure X-Press Update 4.3
http://www.iss.net/download/
Internet Security Systems RealSecure Network Sensor 5.5.2 XPU 3.4
-
Internet Security Systems RealSecure X-Press Update 4.3
http://www.iss.net/download/
Internet Security Systems RealSecure Network Sensor 6.0 XPU 3.4
-
Internet Security Systems RealSecure X-Press Update 4.3
http://www.iss.net/download/
Internet Security Systems RealSecure Network Sensor 6.5
-
Internet Security Systems RealSecure X-Press Update 4.3
http://www.iss.net/download/
References
ISS RealSecure DHCP Signature Remote Denial Of Service Vulnerability
References:
References: