Oct, 2002 : Security Hole Discovered in Symantec Firewall


broadcom.com logo📅 - A security hole has been discovered in the Web proxy component of Symantec's (symantec.com) Enterprise Firewall product, also known as "Simple Secure Webserver 1.1."

The vulnerability concerns the way the Web server handles requests for URLs (uniform resource locators), addresses used to access Web pages and other resources on the Internet.
According to a security advisory posted on Advanced IT Security's Web site, requests from an attacker for registered but unavailable Internet domains cause the Symantec Web server to pause for as long as five minutes waiting for a reply. During that time, the entire firewall ceases to respond to other, legitimate requests, affecting not only Web traffic to the domain that would go through the firewall, but other types of Internet traffic as well.
The "Simple Secure Webserver" appears to wait for a timeout contacting the DNS server, and while doing so the software does not fork and thereby queues or drops all requests coming from other clients. The timeout usually last up to 300 seconds. Sending subsequent requests for other hostnames in the same flawed domain will force the product to stop processing requests for a long time.
Security experts recommend that the Web proxy component be disabled or patched.

broadcom.com Reads: 2713 | Category: General | Source: TheWHIR : Web Host Industry Reviews
URL source: http://www.thewhir.com/marketwatch/sec101802.cfm

Company: Broadcom

Want to add a website news or press release ? Just do it, it's free! Use add web hosting news!