PT-2002-1219 · Avirt · Avirt Gateway Suite
Publicado
2002-03-15
·
Atualizado
2016-10-18
·
CVE-2002-0133
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Avirt Gateway Suite version 4.2
Description
The issue concerns buffer overflows that can be triggered by remote attackers, potentially leading to a denial of service and possibly the execution of arbitrary code. This can occur through two main vectors: (1) sending long header fields to the HTTP proxy, or (2) sending a long string to the telnet proxy.
Recommendations
For Avirt Gateway Suite version 4.2, consider restricting access to the HTTP and telnet proxies as a temporary mitigation measure until a patch is available. Avoid using long header fields in the HTTP proxy and long strings in the telnet proxy to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Avirt Gateway Suite