|
 |
|
Kerio Personal Firewall Hooked Functions Denial of Service
|
|
|
|
|
Secunia Advisory:
|
SA22234
|
|
|
Release Date:
|
2006-10-02
|
|
Last Update:
|
2006-10-05
|
|
|
Critical:
|

Not critical
|
|
Impact:
|
DoS
|
|
Where:
|
Local system
|
|
Solution Status:
|
Unpatched
|
|
| Software: | Kerio Personal Firewall 4.x
|
| | CVE reference: | CVE-2006-5153 (Secunia mirror)
|
|
|
This advisory is currently marked as unpatched! - Companies can be alerted when a patch is released! |
|
|
Description: David Matousek has reported some vulnerabilities in Kerio Personal Firewall, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
The vulnerabilities are caused due to errors within fwdrv.sys and khips.sys when handling the parameters of certain hooked functions. This can be exploited to cause a DoS by calling NtCreateFile, NtDeleteFile, NtLoadDriver, NtMapViewOfSection, NtOpenFile, and NtSetInformationFile with specially crafted parameters.
The vulnerability has been reported in Kerio Personal Firewall 4.3.268, 4.3.246, 4.2.3.912. Other versions may also be affected.
Solution: Restrict access to trusted users only.
Provided and/or discovered by: David Matousek
Changelog: 2006-10-05: Added CVE reference.
Original Advisory: http://www.matousec.com/info/advisori...lidation-of-hooked-SSDT-functions.php
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
9 Related Secunia Security Advisories
|
|
|
1. Kerio Personal Firewall Engine Denial of Service
|
|
2. Kerio Personal/Server Firewall FWDRV Driver Denial of Service
|
|
3. Kerio Products Password Brute Force and Denial of Service
|
|
4. Kerio Personal Firewall Network Rules Security Bypass
|
|
5. Kerio Personal Firewall IP Option Denial of Service Vulnerability
|
|
6. Kerio Personal Firewall Program Execution Protection Feature Bypass
|
|
7. Kerio Personal Firewall URL Handling Denial of Service
|
|
8. Kerio Personal Firewall TCP Stealth Scan Detection Vulnerability
|
|
9. Kerio Personal Firewall Filter Bypass Security Issue
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|