Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
BID:18996
CVE-2006-3787 |Info
Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
| Bugtraq ID: | 18996 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 15 2006 12:00AM |
| Updated: | Jul 28 2006 10:27PM |
| Credit: | Discovery is credited to David Matousek. |
| Vulnerable: |
Sunbelt Software Kerio Personal Firewall 4.3.426 |
| Not Vulnerable: |
Sunbelt Software Kerio Personal Firewall 4.2.3 912 |
Discussion
Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
Sunbelt Kerio Personal Firewall is prone to a denial-of-service vulnerability. This issue can occur when a program calls the 'CreateRemoteThread' Windows API call.
Exploitation of this vulnerability could cause the firewall application to crash. This could expose the computer to further attacks.
The individual who discovered this vulnerability claims to have tested it on Sunbelt Kerio Personal Firewall versions 4.3.246 and 4.2.3.912. They were unable to reproduce the vulnerability on version 4.2.3.912, which is an older release. The vulnerable functionality may have been introduced at some point after the 4.2.3.912 release, but this has not been confirmed.
Sunbelt Kerio Personal Firewall is prone to a denial-of-service vulnerability. This issue can occur when a program calls the 'CreateRemoteThread' Windows API call.
Exploitation of this vulnerability could cause the firewall application to crash. This could expose the computer to further attacks.
The individual who discovered this vulnerability claims to have tested it on Sunbelt Kerio Personal Firewall versions 4.3.246 and 4.2.3.912. They were unable to reproduce the vulnerability on version 4.2.3.912, which is an older release. The vulnerable functionality may have been introduced at some point after the 4.2.3.912 release, but this has not been confirmed.
Exploit / POC
Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
Solution:
Although Kerio Personal Firewall 4.2.3.912 does not appear to be affected by this issue, 4.2.3.912 is an earlier release than the affected version. Symantec advises against downgrading to 4.2.3.912 unless absolutely necessary, since the older release may be prone to other vulnerabilities.
Reports indicate the vendor has released an updated version to address this issue. Please contact the vendor for more information.
Solution:
Although Kerio Personal Firewall 4.2.3.912 does not appear to be affected by this issue, 4.2.3.912 is an earlier release than the affected version. Symantec advises against downgrading to 4.2.3.912 unless absolutely necessary, since the older release may be prone to other vulnerabilities.
Reports indicate the vendor has released an updated version to address this issue. Please contact the vendor for more information.
References
Sunbelt Kerio Personal Firewall CreateRemoteThread Denial of Service Vulnerability
References:
References:
- Kerio Personal Firewall (Sun-Belt Software)
- Kerio Terminating 'kpf4ss.exe' using internal runtime error Vulnerability (David Matousek
) - Kerio Terminating 'kpf4ss.exe' using internal runtime error Vulnerability (David Matousek
)