Short Name |
MISC:KERIO-AUTH-OF |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
MISC |
Keywords |
Kerio Personal Firewall Authentication Overflow |
Release Date |
2006/03/02 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in Kerio Personal Firewall. Kerio Personal Firewall 2.1.4 and earlier are vulnerable. Attackers can use an invalid authentication, attempting to exploit this vulnerability and execute arbitrary code on the target host.
A buffer-overflow vulnerability has been discovered in Kerio Personal Firewall. The problem occurs during the administration authentication process. An attacker could exploit this vulnerability by forging a malicious packet containing an excessive data size. The application then reads this data into a static memory buffer without first performing sufficient bounds checking. Successful exploits of this vulnerability may allow an attacker to execute arbitrary commands on a target system, with the privileges of the firewall. Note that this vulnerability affects Kerio Personal Firewall 2.1.4 and earlier.