PT-2002-1996 · Symantec · Symantec Gateway Security+3
Publicado
2002-10-28
·
Atualizado
2016-10-18
·
CVE-2002-0990
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Symantec Enterprise Firewall versions 6.5.2 through 7.0
Raptor Firewall versions 6.5 and 6.5.3
VelociRaptor (affected versions not specified)
Symantec Gateway Security (affected versions not specified)
Description:
The issue allows remote attackers to cause a denial of service, specifically connection resource exhaustion, by making multiple connection requests to domains with unresponsive or non-existent DNS servers. This results in a long timeout.
Recommendations:
For Symantec Enterprise Firewall versions 6.5.2 through 7.0, consider implementing rate limiting on connection requests to mitigate the risk of denial of service.
For Raptor Firewall versions 6.5 and 6.5.3, restrict access to the web proxy component until a fix is available.
For VelociRaptor and Symantec Gateway Security, at the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Raptor Firewall
Symantec Enterprise Firewall
Symantec Gateway Security
Velociraptor