Denial of Service in ISS RealSecure

A Denial of Service (DoS) condition exists in Internet Security Systems’ RealSecure Network Sensor.

Ken Pfeil

May 1, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported April 30, 2002, byInternet Security Systems.

VERSIONAFFECTED

 

  • RealSecure Network Sensor 6.5

  • RealSecure Network Sensor 6.0, XPU 3.4 and later

  • RealSecure Network Sensor 5.x, XPU 3.4 and later

DESCRIPTION

ADenial of Service (DoS) condition exists in Internet Security Systems’RealSecure Network Sensor. Specifically, a vulnerability in the threeinformational signatures associated with DHCP can result in a segmentation faultor exception error. An attacker can exploit this vulnerability by sendingspecially crafted DHCP traffic, causing the sensor to malfunction or crash.

 


VENDOR RESPONSE

 

Thevendor, Internet Security Systems, has issued X-PressUpdate 4.3, which contains a fix for this vulnerability.

 

CREDIT
Discovered by Internet Security Systems

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like