PT-2002-1219 · Avirt · Avirt Gateway Suite
Published
2002-03-15
·
Updated
2016-10-18
·
CVE-2002-0133
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Avirt Gateway Suite version 4.2
Description
The issue concerns buffer overflows that can be triggered by remote attackers, potentially leading to a denial of service and possibly the execution of arbitrary code. This can occur through two main vectors: (1) sending long header fields to the HTTP proxy, or (2) sending a long string to the telnet proxy.
Recommendations
For Avirt Gateway Suite version 4.2, consider restricting access to the HTTP and telnet proxies as a temporary mitigation measure until a patch is available. Avoid using long header fields in the HTTP proxy and long strings in the telnet proxy to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avirt Gateway Suite