Hosting generously provided by
|
|
|
Welcome to the Firewalls section within our archives.
Please select a advisory below by clicking on it.
Last Modified: 1/2/2005
The HTTP proxy can be used for more then HTTP.
Denial of Service condition on version 3.0.
Versions 1.5.3 and 1.5.4 contain a denial of service attack.
Versions before 5.0.35 can be crashed if a specially crafted packet is sent.
A hole exists that can allow a attacker to gain an encrypted password
from a configuration file. This password is easy to decrypt and can allow
further exploitation of remote host.
A hole exists that can allow a attacker to gain administrative priviledges on
a cisco PIX firewall via the web interface.
Multiple buffer overflows in some CGI programs this product uses
can allow a attacker to execute commands remotely.
It is possible to execute commands on this firewall and bypass the filters.
This is the CERT warning of this advisory.
BY sending a specially crafted url you can bypass the filter functions
of this product.
A hole exists that allows a attacker to send a .. request to this firewall
on port 4096 and read remote files.
A hole exists in the PIX firewall that can release some information
on the firewalls statistics. (Original Bugtraq post Included)
A hole exists that could allow someone to take control over
the management station. This of course isn't a good thing.
A hole exists that could allow a attacker to send certain
types of packets around a firewall.
Interscan VirusWall For NT Advisories
There are a few overflows in various dll files from this product.
If you are running it ether unplug it or read these advisories.
|
|
|
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
|
|
|
Subscribe to CGISecurity.com
|
|

|
|
|
|
The Web Security Mailing List
|
|
|
|
|
Contact us
|
Post News, get linkage!
|
|
|

|