Kerio WinRoute Firewall May Crash Due to Malformed HTTP Headers
|
|
SecurityTracker Alert ID: 1009548
|
|
CVE Reference: GENERIC-MAP-NOMATCH
(Links to External Site)
|
Date: Mar 24 2004
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): prior to 5.1.10
|
Description: A vulnerability was reported in the Kerio WinRoute Firewall. The firewall may crash.
The vendor reported that there is a flaw in the parsing of HTTP headers that may cause the firewall to crash.
|
Impact: The firewall may crash when parsing a specially crafted HTTP header.
|
Solution: The vendor has released a fixed version (5.1.10), available at:
http://www.kerio.com/kwf_download.html
|
Vendor URL: www.kerio.com/kwf_home.html (Links to External Site)
|
Cause: Exception handling error
|
Underlying OS: Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Wed, 24 Mar 2004 10:57:43 -0500
Subject: http://www.kerio.com/kwf_history.html
|
http://www.kerio.com/kwf_history.html
> Version 5.1.10 - March 1, 2004
> - fixed crash in HTTP header parser
|
|