Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Computer Associates (CA) eTrust Intrusion Detection 3.0 allows remote attackers to cause a denial of service via large size values that are not properly validated before calling the CPImportKey function in the Crypto API.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CA eTrust Intrusion Detection 安全漏洞
Vulnerability Description
CA eTrust Intrusion Detection是美国CA公司的一种完整的会话安全解决方案。 CA eTrust Intrusion Detection 3.0存在安全漏洞,漏洞的起因是对Microsoft的加密API函数CPImportKey所传送的值执行了不充分的检查。CPImportKey函数通过传送给CPImportKey的数据blob中所提供的数据来确定某些缓冲区分配的大小,因此如果包装函数在调用CPImportKey前没有验证传送给Crypto API的数据的话,就可能导致分配很大的
CVSS Information
N/A
Vulnerability Type
N/A