E-Mail:
Author Avatar

Kerio Personal Firewall Denial of Service Vulnerability

Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Vendor Patch

eEye Digital Security has reported a vulnerability in Kerio Personal Firewall, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in “FWDRV.SYS” when performing low-level processing of TCP, UDP, and ICMP packets. This can be exploited to consume all available CPU resources by sending a specially-crafted packet containing an IP option followed by a length field with the value of “0×00.”

Successful exploitation causes the system to stop responding and requires the system to be restarted.

The vulnerability affects versions 4.0.0 through 4.1.1.

Solution: Update to version 4.1.2.

What Do You Think?

 


Anti-Spam Image

Want to Start a Blog Here for Free?

Are you an expert in one subject or another? If your goal is to help others and dispense hard-earned information back to the community, stake a claim on your very own Lockergnome blog today! You can write about anything - no matter the topic. Sign-up to start blogging!

Author Avatar
Download, Freeware - Sep 5, 2008

ThunderBrowse v3.2.1.9

Author Avatar
Download, Freeware - Sep 1, 2008

BitMeter v3.5.7

70 queries / 0.698 seconds.