Kerio Personal Firewall Remote Authentication Packet Buffer Overflow Vulnerability
BID:7180
Info
Kerio Personal Firewall Remote Authentication Packet Buffer Overflow Vulnerability
| Bugtraq ID: | 7180 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0220 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 28 2003 12:00AM |
| Updated: | Oct 16 2007 06:27PM |
| Credit: | The discovery of this vulnerability has been credited to Emiliano Kargieman, Hernán Gips and Javier Burroni from Core Security Technologies. It should be noted that the s0h group has published an unofficial patch to address this issue. |
| Vulnerable: |
Kerio Personal Firewall 2 2.1.4 Kerio Personal Firewall 2 2.1.3 Kerio Personal Firewall 2 2.1.2 Kerio Personal Firewall 2 2.1.1 Kerio Personal Firewall 2 2.1 |
| Not Vulnerable: |
Kerio Personal Firewall 2 2.1.5 |
Discussion
Kerio Personal Firewall Remote Authentication Packet Buffer Overflow Vulnerability
A buffer-overflow vulnerability has been discovered in Kerio Personal Firewall. The problem occurs during the administration authentication process. An attacker could exploit this vulnerability by forging a malicious packet containing an excessive data size. The application then reads this data into a static memory buffer without first performing sufficient bounds checking.
Successful exploits of this vulnerability may allow an attacker to execute arbitrary commands on a target system, with the privileges of the firewall.
Note that this vulnerability affects Kerio Personal Firewall 2.1.4 and earlier.
A buffer-overflow vulnerability has been discovered in Kerio Personal Firewall. The problem occurs during the administration authentication process. An attacker could exploit this vulnerability by forging a malicious packet containing an excessive data size. The application then reads this data into a static memory buffer without first performing sufficient bounds checking.
Successful exploits of this vulnerability may allow an attacker to execute arbitrary commands on a target system, with the privileges of the firewall.
Note that this vulnerability affects Kerio Personal Firewall 2.1.4 and earlier.
Exploit / POC
Kerio Personal Firewall Remote Authentication Packet Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has released a proof-of-concept python exploit that triggers a denial of service.
An exploit has been made available by Alin-Adrian Anton <[email protected]>
An exploit has been developed by ThreaT of the Skin of Humanity group.
An exploit has been made available as part of the Metasploit Framework project.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has released a proof-of-concept python exploit that triggers a denial of service.
An exploit has been made available by Alin-Adrian Anton <[email protected]>
An exploit has been developed by ThreaT of the Skin of Humanity group.
An exploit has been made available as part of the Metasploit Framework project.
References
Kerio Personal Firewall Remote Authentication Packet Buffer Overflow Vulnerability
References:
References:
- Kerio Homepage (Kerio)
- Kerio PF Administration exploit (CORE Security)
- s0h: Kerio Personal Firewall and Tiny Personal Firewall remote exploit/patc (descript
)