Axent Raptor Denial of Service Vulnerability
BID:736
Info
Axent Raptor Denial of Service Vulnerability
| Bugtraq ID: | 736 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 1999 12:00AM |
| Updated: | Oct 21 1999 12:00AM |
| Credit: | This was discovered by the CERIAS labs at perdue (cs.perdue.edu) and posted to BugTraq on October 21, 1999. |
| Vulnerable: |
Axent Raptor 6.0 |
| Not Vulnerable: | |
Discussion
Axent Raptor Denial of Service Vulnerability
It is possible to remotely lock Axent Raptor firewalls by sending them packets with malformed IP options fields. According to an advisory posted to bugtraq by the perdue CERIAS labs, setting the SECURITY and TIMESTAMP IP options length to 0 can cause an infinite loop to occur within the code that handles the options (resulting in the software freezing). A consequence of this is a remote denial of service.
It is possible to remotely lock Axent Raptor firewalls by sending them packets with malformed IP options fields. According to an advisory posted to bugtraq by the perdue CERIAS labs, setting the SECURITY and TIMESTAMP IP options length to 0 can cause an infinite loop to occur within the code that handles the options (resulting in the software freezing). A consequence of this is a remote denial of service.
Exploit / POC
Axent Raptor Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Axent Raptor Denial of Service Vulnerability
Solution:
Axent has released a hotfix for this problem which is available at:
ftp://ftp.raptor.com/pub/patches/V6.0/hotfixes.post602/dom/DOS-attack/
The 6.02 upgrade is available at:
ftp://ftp.raptor.com/pub/patches/V6.0/6.02Patch/dom/
Solution:
Axent has released a hotfix for this problem which is available at:
ftp://ftp.raptor.com/pub/patches/V6.0/hotfixes.post602/dom/DOS-attack/
The 6.02 upgrade is available at:
ftp://ftp.raptor.com/pub/patches/V6.0/6.02Patch/dom/
References
Axent Raptor Denial of Service Vulnerability
References:
References: