Symantec Enterprise Firewall iskampd Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1011062
|
|
SecurityTracker URL: http://securitytracker.com/id?1011062
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Aug 25 2004
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 7.0, 7.0.4
|
Description: A vulnerability was reported in Symantec Enterprise Firewall. A remote user can cause denial of service conditions.
The vendor reported that a remote user can cause denial of service conditions in isakmpd on the target system. No further details
were provided.
The original advisories are available at:
ftp://ftp.symantec.com/public/updates/entrust-70s-readme.txt
ftp://ftp.symantec.com/public/updates/entrust
-70w-readme.txt
ftp://ftp.symantec.com/public/updates/entrust-704s-readme.txt
ftp://ftp.symantec.com/public/updates/entrust-704w-readme.txt
|
Impact: A remote user can cause denial of service conditions on the target system.
|
Solution: The vendor has issued hotfixes (SG7004-20040715-00). Hotfix HB7000-20040503-00 is a prerequisite.
For 7.0 and 7.0.4 on Solaris:
ftp://ftp.symantec.com/public/update
s/entrust-704s-3des.tar.Z
ftp://ftp.symantec.com/public/updates/entrust-704s-des.tar.Z
For 7.0 and 7.0.4 for Windows NT/2000:
ftp://ftp.symantec.com/public/updates
/entrust-704w-3des.exe
ftp://ftp.symantec.com/public/updates/entrust-704w-des.exe
|
Vendor URL: www.symantec.com/ (Links to External Site)
|
Cause: Not specified
|
Underlying OS: UNIX (Solaris - SunOS), Windows (NT), Windows (2000)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Aug 25, 2004
Subject: Symantec Enterprise Firewall 7.0
|
ftp://ftp.symantec.com/public/updates/entrust-70s-readme.txt
ftp://ftp.symantec.com/public/updates/entrust-70w-readme.txt
ftp://ftp.symantec.com/public/updates/entrust-704s-readme.txt
ftp://ftp.symantec.com/public/updates/entrust-704w-readme.txt
Symantec issued hotfixes for Symantec Enterprise Firewall 7.0 (SG7004-20040715-00) to
correct the vulnerability reported in CAN-2004-0369.
HB7000-20040503-00 is a prerequisite.
For 7.0 and 7.0.4 on Solaris:
ftp://ftp.symantec.com/public/updates/entrust-704s-3des.tar.Z
ftp://ftp.symantec.com/public/updates/entrust-704s-des.tar.Z
For 7.0 and 7.0.4 for Windows NT/2000:
ftp://ftp.symantec.com/public/updates/entrust-704w-3des.exe
ftp://ftp.symantec.com/public/updates/entrust-704w-des.exe
|
|