RE: DoS Vulnerability found in ISS BlackICE Defender

From: Jensenne Roculan (jroculan@securityfocus.com)
Date: 02/06/02


Date: Wed, 6 Feb 2002 13:23:15 -0700 (MST)
From: Jensenne Roculan <jroculan@securityfocus.com>
To: Robert Graham <robert_david_graham@yahoo.com>


> Only the "host-based IDS" is affected, not the "network-based IDS". The
> RealSecure Network Sensor is unaffected. The BlackICE "Sentry" network
sensors
> are likewise unaffected.

Yes, you're right. Sorry, I should have been more explicit, the advisory
states that RealSecure _Server Sensor_ is affected in addition to
BlackICE Defender and Agent.

> Fixing the bug is easy. If you have automatic updates turned on, then
you may
> already be updated. If you do manual updates, select the "update" menu
item. If
> you are a corporate customer, update ICEcap, which will then
automatically
> update all the desktop/server sensors.

Thanks for the update!

Cheers,

Jensenne Roculan
SecurityFocus - http://www.securityfocus.com
ARIS - http://aris.securityfocus.com
(403) 213-3939 ext. 229