PT-2001-2633 · Zonealarm · Zonealarm Pro+1

Published

2001-12-31

·

Updated

2008-09-05

·

CVE-2001-1548

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ZoneAlarm versions 2.1 through 2.6 ZoneAlarm Pro versions 2.4 and 2.6
Description The issue allows local users to bypass filtering by utilizing non-standard TCP packets created with non-Windows protocol adapters.
Recommendations For ZoneAlarm versions 2.1 through 2.6, update to a version that is not affected by this issue. For ZoneAlarm Pro versions 2.4 and 2.6, update to a version that is not affected by this issue. As a temporary workaround, consider restricting the use of non-Windows protocol adapters to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1548

Affected Products

Zonealarm
Zonealarm Pro