Sygate Secure Enterprise Enforcer Remote Denial Of Service Vulnerability
BID:10910
Info
Sygate Secure Enterprise Enforcer Remote Denial Of Service Vulnerability
| Bugtraq ID: | 10910 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0931 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | This vulnerability was discovered and announced by Martin O'Neal of Corsaire Security. |
| Vulnerable: |
Sygate Secure Enterprise 4.0 Sygate Secure Enterprise 3.5 MR3 Sygate Secure Enterprise 3.5 MR1 Sygate Secure Enterprise 3.5 Sygate Secure Enterprise 3.0 |
| Not Vulnerable: | |
Discussion
Sygate Secure Enterprise Enforcer Remote Denial Of Service Vulnerability
Sygate Enforcer is reported to be susceptible to a remote denial of service vulnerability.
Malformed UDP packets can be broadcast on a local network segment, and reportedly crash all affected applications that receive it. These UDP discovery packets can also be send to unicast addresses, and can therefore be routed to remote networks to crash targeted computers. The origin of these packets could also likely be spoofed, hiding the source of the attack.
Sygate Enforcer versions 4.0 and prior are reported to be affected by this vulnerability.
Sygate Enforcer is reported to be susceptible to a remote denial of service vulnerability.
Malformed UDP packets can be broadcast on a local network segment, and reportedly crash all affected applications that receive it. These UDP discovery packets can also be send to unicast addresses, and can therefore be routed to remote networks to crash targeted computers. The origin of these packets could also likely be spoofed, hiding the source of the attack.
Sygate Enforcer versions 4.0 and prior are reported to be affected by this vulnerability.
Exploit / POC
Sygate Secure Enterprise Enforcer Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sygate Secure Enterprise Enforcer Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Sygate Secure Enterprise Enforcer Remote Denial Of Service Vulnerability
References:
References:
- Sygate Homepage (Sygate)
- Corsaire Security Advisory - Sygate Enforcer discovery packet DoS issue ("advisories"
)