The buffer overflow trigger in Cisco Security Agent (CSA) before 4.0.3 build 728 waits five minutes for a user response before terminating the process, which could allow remote attackers to bypass the buffer overflow protection by sending additional buffer overflow attacks within the five minute timeout period.
References
| Link | Resource |
|---|---|
| http://www.ciac.org/ciac/bulletins/p-036.shtml | Vendor Advisory |
| http://www.cisco.com/warp/public/707/cisco-sa-20041111-csa.shtml | Vendor Advisory |
| http://www.securityfocus.com/bid/11659 | Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/18037 | |
| http://www.ciac.org/ciac/bulletins/p-036.shtml | Vendor Advisory |
| http://www.cisco.com/warp/public/707/cisco-sa-20041111-csa.shtml | Vendor Advisory |
| http://www.securityfocus.com/bid/11659 | Vendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/18037 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-01-10 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-1112
Mitre link : CVE-2004-1112
CVE.ORG link : CVE-2004-1112
JSON object : View
Products Affected
cisco
- security_agent
okena
- stormwatch
CWE
