CVE-2007-1005Insecure Temporary File in Etrust Intrusion Detection

Severity
7.8HIGHNVD
EPSS
3.8%
top 11.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 2
Latest updateMay 1

Description

Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-29mq-6jwf-w4hx: Heap-based buffer overflow in SW3eng2022-05-01
CVEList
CVE-2007-1005: Heap-based buffer overflow in SW3eng2007-03-02

💥Exploits & PoCs

1
Exploit-DB
Ekiga 2.0.5 - 'GetHostAddress' Remote Denial of Service2009-07-24

📋Vendor Advisories

1
Red Hat
sysstat insecure temporary file usage2007-08-10
CVE-2007-1005 — Insecure Temporary File | cvebase