Snapgear Lite+ Firewall IPSEC Denial of Service Vulnerability
BID:4659
Info
Snapgear Lite+ Firewall IPSEC Denial of Service Vulnerability
| Bugtraq ID: | 4659 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0603 |
| Remote: | Yes |
| Local: | No |
| Published: | May 02 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Andreas Sandor ([email protected]) & Peter Gründl ([email protected]). |
| Vulnerable: |
Snapgear Lite+ Firewall 1.5.3 |
| Not Vulnerable: |
Snapgear Lite+ Firewall 1.6 .0 Snapgear Lite+ Firewall 1.5.4 |
Discussion
Snapgear Lite+ Firewall IPSEC Denial of Service Vulnerability
Snapgear Lite+ is a device with integrated firewall, routing, and VPN support.
Sending a 0 length UDP packet through the firewall when IPSEC is enabled will cause the IPSEC implementation to fail. This may result in a denial of VPN/tunnel service.
Snapgear Lite+ is a device with integrated firewall, routing, and VPN support.
Sending a 0 length UDP packet through the firewall when IPSEC is enabled will cause the IPSEC implementation to fail. This may result in a denial of VPN/tunnel service.
Solution / Fix
Snapgear Lite+ Firewall IPSEC Denial of Service Vulnerability
Solution:
The vendor has released a firmware upgrade.
Snapgear Lite+ Firewall 1.5.3
Solution:
The vendor has released a firmware upgrade.
Snapgear Lite+ Firewall 1.5.3
-
Snapgear SnapGearLITE_LITE+_v1.6.0_20020429_imagez.bin
Linux version.
http://www.snapgear.com/ftp/snapgear/firmware/SnapGearLITE_LITE+_v1.6. 0_20020429_imagez.bin -
Snapgear SnapGearLITE_LITE+_v1.6.0_20020429_netflash.exe
Windows version.
http://www.snapgear.com/ftp/snapgear/firmware/SnapGearLITE_LITE+_v1.6. 0_20020429_netflash.exe
References
Snapgear Lite+ Firewall IPSEC Denial of Service Vulnerability
References:
References:
- Snapgear Homepage (Snapgear)