Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Kerio WinRoute Firewall May Crash Due to Malformed HTTP Headers

Mar 24, 2004 12:31PM PST

SecurityTracker Alert ID: 1009548
CVE Reference: GENERIC-MAP-NOMATCH
Date: Mar 24 2004

Impact: Denial of service via network

Fix Available: Yes Vendor Confirmed: Yes

Version(s): prior to 5.1.10

Description: A vulnerability was reported in the Kerio WinRoute Firewall. The firewall may crash.

The vendor reported that there is a flaw in the parsing of HTTP headers that may cause the firewall to crash.

Impact: The firewall may crash when parsing a specially crafted HTTP header.

Solution: The vendor has released a fixed version (5.1.10), available at:

http://www.kerio.com/kwf_download.html

Vendor URL: www.kerio.com/kwf_home.html

Cause: Exception handling error

Underlying OS: Windows (Any)

http://www.securitytracker.com/alerts/2004/Mar/1009548.html

Discussion is locked