Editor Login | Register
Ekle

> World > Security
Webwasher URL Processing Denial of Service Vulnerability - Security - World -
CWRedLight
(Date : 04.04.2008 17:10:21)


Webwasher URL Processing Denial of Service Vulnerability
Webwasher URL Processing Denial of Service Vulnerability

Secunia Advisory: SA29674  
Release Date: 2008-04-04

Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch

Software:Webwasher 6.x
Webwasher CSM Suite 5.x
WebWasher EE
WebWasher PG
Description:
A vulnerability has been reported in Webwasher, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in the processing of URLs when running on newer Linux system. This can be exploited to freeze the service via a specially crafted URL.

The vulnerability is reported in the following products:
* Webwasher appliances 6.x (CGLinux 4 or 5) prior to build number 3150
* Webwasher software versions prior to versions 6.6.3 build 3150 or 5.3.0 build 3159 running on:
- RedHat Enterprise Linux 4
- Debian Linux 4
- SLES 10

Solution:
Update to versions 6.6.3 build 3150 or 5.3.0 build 3159:
https://extranet.webwasher.com/download/csm/index.html

Provided and/or discovered by:
The vendor credits National Australia Bank Security Assurance.











Derecelendir
Kaynak http://secunia.com/advisories/29674/
İçerik İhbarı
Bağlantılar: bilgininefendisi.net

Open Source Document Project AUP&TOS