NetScreen H.323 Session State Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1005708 |
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Nov 25 2002
|
Impact: Denial of service via network
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Version(s): 2.8, 3.0, 3.1, 4.0
|
Description: A denial of service vulnerability was reported in NetScreen's firewall/VPN appliances. A remote user can prevent the firewall from processing additional sessions.
It is reported that a remote user can exploit a flaw in the processing of H.323 control sessions to cause the firewall's session
table to fill up, preventing additional sessions.
According to the report, half-open H.323 sessions may remain until the defined
H.323 session timeout interval (apparently this is typically 36 hours) instead of being closed out at a more frequent interval.
NetScreen
reports that the system is only vulnerable if configured to permit H.323 or Netmeeting services.
NetScreen credits Stephen Gill
with reporting this flaw.
|
Impact: A remote user can deny service to firewall users.
|
Solution: The vendor has indicated that you can install a maintenance release (see the vendor advisory for the release table) or upgrade to
ScreenOS 4.0.1. The vendor advisory is available at:
http://www.netscreen.com/support/alerts/Potential_H_323_Denial_of_Service.html
Registered
users with a valid service contract can download updates to:
http://www.netscreen.com/support/updates.html
|
Vendor URL: www.netscreen.com/support/alerts/Potential_H_323_Denial_of_Service.html (Links to External Site)
|
Cause: State error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 25 Nov 2002 17:53:13 -0500
Subject: NetScreen Security Alert 52020
|
http://www.netscreen.com/support/alerts/Potential_H_323_Denial_of_Service.html
NetScreen issued Security Alert 52020 regarding a denial of service vulnerability in
NetScreen's firewall/VPN appliances
Versions: ScreenOS 2.8, 3.0, 3.1, 4.0
A remote user can exploit a flaw in the processing of H.323 control sessions to cause the
firewall's session table to fill up, preventing additional sessions.
According to the report, half-open H.323 sessions may remain until the defined H.323
session timeout interval (apparently this is typically 36 hours) instead of being closed
out at a more frequent interval.
NetScreen reports that the system is only vulnerable if configured to permit H.323 or
Netmeeting services.
The vendor has indicated that you can install a maintenance release (see the vendor
advisory for the release table) or upgrade to ScreenOS 4.0.1.
Registered users with a valid service contract can download updates to:
http://www.netscreen.com/support/updates.html
NetScreen credits Stephen Gill with reporting this flaw.
|
|