---------------------------------------------------------------------- Secunia is proud to announce the availability of the Secunia Software Inspector. The Secunia Software Inspector is a free service that detects insecure versions of software that you may have installed in your system. When insecure versions are detected, the Secunia Software Inspector also provides thorough guidelines for updating the software to the latest secure version from the vendor. Try it out online: http://secunia.com/software_inspector/ ---------------------------------------------------------------------- TITLE: CA eTrust Intrusion Detection Key Length Value Denial of Service SECUNIA ADVISORY ID: SA24309 VERIFY ADVISORY: http://secunia.com/advisories/24309/ CRITICAL: Less critical IMPACT: DoS WHERE: >From local network SOFTWARE: eTrust Intrusion Detection 3.x http://secunia.com/product/3390/ DESCRIPTION: A vulnerability has been reported in CA eTrust Intrusion Detection, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an input validation error of key length values in the remote administration interface and can be exploited to crash the administration service. The vulnerability is reported in the following versions: * 2.0 SP1 (SW3eng.exe prior to 2.0.0.41) * 3.0 (SW3eng.exe prior to 3.0.2.07) * 3.0 SP1 (SW3eng.exe prior to 3.0.5.80) SOLUTION: Apply patches. eTrust Intrusion Detection 3.0 SP1: Apply patch QO85469. http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO85469 eTrust Intrusion Detection 3.0: Apply patch QO85472. http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO85472 eTrust Intrusion Detection 2.0 SP1: Apply patch QO85488. http://supportconnect.ca.com/sc/redir.jsp?reqPage=search&searchID=QO85488 PROVIDED AND/OR DISCOVERED BY: Discovered by an anonymous person and reported via iDefense Labs. ORIGINAL ADVISORY: CA: http://supportconnectw.ca.com/public/ca_common_docs/eid_secnotice.asp iDefense Labs: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=484 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------