Ingate Firewall May Let Remote Users Setup Sessions By Sending SYN+RST Packets
|
|
SecurityTracker Alert ID: 1007789
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Sep 23 2003
|
Impact: Host/resource access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 3.2.1
|
Description: A vulnerability was reported in the Ingate Firewalls. A remote user may be able to initiate sessions through the firewall in certain cases.
It is reported that a remote user can send a SYN+RST packet through the firewall in the reply (return) direction when TCP packet
filtering is used in the firewall. Some hosts may respond to this packet and set up a TCP connection that should otherwise have
been blocked by the firewall.
|
Impact: A remote user may be able to set up a connection through the firewall to certain hosts in certain cases.
|
Solution: The fixed inGate version (3.2.1) is available at:
http://www.ingate.com/upgrades/
|
Vendor URL: www.ingate.com/relnote-321.php (Links to External Site)
|
Cause: Access control error, State error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 23 Sep 2003 07:18:11 -0400
Subject: http://www.ingate.com/relnote-321.php
|
> Release notice for Ingate Firewall 3.2.1 and Ingate SIParator™ 3.2.1
inGate reported two vulnerabilities in their firewall products:
1) A remote user can reportedly send a SYN+RST packet through the firewall in the reply
(return) direction when TCP packet filtering is used in the firewall. Some hosts may
respond to this packet and set up a TCP connection that should otherwise have been blocked
by the firewall.
2) The firewall is affected by the Netfilter FTP NAT vulnerability described in CVE:
CAN-2003-0467.
The fixed inGate version is available at:
http://www.ingate.com/upgrades/
|
|