Denial of Service in ISS RealSecure
A Denial of Service (DoS) condition exists in Internet Security Systems’ RealSecure Network Sensor.
May 1, 2002
Reported April 30, 2002, byInternet Security Systems.
VERSIONAFFECTED
RealSecure Network Sensor 6.5
RealSecure Network Sensor 6.0, XPU 3.4 and later
RealSecure Network Sensor 5.x, XPU 3.4 and later
DESCRIPTION
ADenial of Service (DoS) condition exists in Internet Security Systems’RealSecure Network Sensor. Specifically, a vulnerability in the threeinformational signatures associated with DHCP can result in a segmentation faultor exception error. An attacker can exploit this vulnerability by sendingspecially crafted DHCP traffic, causing the sensor to malfunction or crash.
VENDOR RESPONSE
Thevendor, Internet Security Systems, has issued X-PressUpdate 4.3, which contains a fix for this vulnerability.
CREDIT
Discovered by Internet Security Systems
About the Author
You May Also Like