ZoneAlarm Denial of Service Vulnerability
- 0
- Add a Comment
- No Related Post
CRITICAL:
Less criticalIMPACT:
DoSWHERE:
From remoteSOFTWARE:
ZoneAlarm Security Suite 5.x, ZoneAlarm Pro 5.x, ZoneAlarm Pro 4.x, ZoneAlarm Pro 3.xDESCRIPTION:
Nicolas Robillard has reported a vulnerability in ZoneAlarm Pro and
ZoneAlarm Security Suite, which can be exploited by malicious people
to cause a DoS (Denial of Service).The vulnerability is caused due to an error in the Ad-Blocking
feature (disabled by default) when processing JavaScript and can be
exploited by tricking a user into visiting a malicious web site
containing specially crafted JavaScript.Successful exploitation causes the system to become unstable or stop
responding completely.SOLUTION:
Update to version 5.5.062 or later via the “Check For Update”
feature.PROVIDED AND/OR DISCOVERED BY:
Nicolas RobillardORIGINAL ADVISORY:
http://download.zonelabs.com/bin/free/securityAlert/18.html
