Flaw in Kerio Firewall

Secunia has issued an advisory about vulnerability in Kerio Personal Firewall that, if exploited, could cause the system to stop responding. "The vulnerability is caused due to an error in ‘FWDRV.SYS’ when performing low-level processing of TCP, UDP, and ICMP packets. This can be exploited to consume all available CPU resources by sending a specially-crafted packet containing an IP option followed by a length field with the value of ’0×00.’ Successful exploitation causes the system to stop responding and requires the system to be restarted. The vulnerability affects versions 4.0.0 through 4.1.1.” A patch is available from Kerio. http://secunia.com/advisories/13030/ http://www.kerio.com/security_advisory.html

Related posts:

  1. Flaw in Word 2000/2002
  2. Serious flaw in AOL instant messenger
  3. Flaw In Winsock proxy service/ISA firewall service
  4. Yet another unpatched IE browser flaw
  5. Serious security flaw in PHP
= Paid content

All Windows Secrets articles posted on 2005-01-20: