Vulnerability CVE-2005-1928


Published: 2005-12-14   Modified: 2012-02-12

Description:
Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of crafted packets with a certain "magic value" to port 5005, which also leads to a memory leak.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Trend Micro ServerProtect EarthAgent Remote DoS Vulnerability
Pedram Amini
15.12.2005

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.8/10
6.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Trend micro -> Serverprotect earthagent 

 References:
http://www.vupen.com/english/advisories/2005/2907
http://www.securityfocus.com/bid/15868
http://www.osvdb.org/21773
http://www.idefense.com/application/poi/display?id=356&type=vulnerabilities
http://solutionfile.trendmicro.com/SolutionFile/25254/en/Hotfix_Readme_SPNT5_58_B1137.txt
http://securitytracker.com/id?1015358
http://securityreason.com/securityalert/259
http://secunia.com/advisories/18038
http://kb.trendmicro.com/solutions/search/main/search/solutionDetail.asp?solutionID=25254

Copyright 2024, cxsecurity.com

 

Back to Top