WinGate SMTP Session Invalid State Remote Denial Of Service Vulnerability
BID:25272
Info
WinGate SMTP Session Invalid State Remote Denial Of Service Vulnerability
| Bugtraq ID: | 25272 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4335 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2007 12:00AM |
| Updated: | May 07 2015 05:36PM |
| Credit: | Stephen Fewer of Harmony Security is credited with the discovery of this vulnerability. |
| Vulnerable: |
Qbik WinGate 6.1.4 .1099 Qbik WinGate 6.1.3 .1096 Qbik WinGate 6.1.2 .1094 Qbik WinGate 6.1.1 .1077 Qbik WinGate 6.0.3 build 1005 Qbik WinGate 6.0.2 build 1001 Qbik WinGate 6.0.2 build 1000 Qbik WinGate 6.0.1 build 995 Qbik WinGate 6.0.1 build 993 Qbik WinGate 6.0 .0 Qbik WinGate 5.0 Qbik WinGate 6.2 Qbik WinGate 6.1 |
| Not Vulnerable: |
Qbik WinGate 6.2.2 |
Discussion
WinGate SMTP Session Invalid State Remote Denial Of Service Vulnerability
WinGate is prone to a denial-of-service vulnerability because the application fails to sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
This issue affects versions prior to WinGate 6.2.2.
WinGate is prone to a denial-of-service vulnerability because the application fails to sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
This issue affects versions prior to WinGate 6.2.2.
Exploit / POC
WinGate SMTP Session Invalid State Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
WinGate SMTP Session Invalid State Remote Denial Of Service Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Qbik WinGate 6.2
Qbik WinGate 6.1
Qbik WinGate 5.0
Qbik WinGate 6.0 .0
Qbik WinGate 6.0.1 build 995
Qbik WinGate 6.0.1 build 993
Qbik WinGate 6.0.2 build 1001
Qbik WinGate 6.0.2 build 1000
Qbik WinGate 6.0.3 build 1005
Qbik WinGate 6.1.1 .1077
Qbik WinGate 6.1.2 .1094
Qbik WinGate 6.1.3 .1096
Qbik WinGate 6.1.4 .1099
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Qbik WinGate 6.2
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.1
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 5.0
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.0 .0
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.0.1 build 995
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.0.1 build 993
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.0.2 build 1001
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.0.2 build 1000
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.0.3 build 1005
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.1.1 .1077
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.1.2 .1094
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.1.3 .1096
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
Qbik WinGate 6.1.4 .1099
-
Winged WinGate6.2.2.1137-USE.EXE
http://downloads.qbik.com/qbiknz2/downloads/WinGate6.2.2.1137-USE.EXE
References
WinGate SMTP Session Invalid State Remote Denial Of Service Vulnerability
References:
References: