|
Mandiant First Response Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA23393
|
|
|
Release Date:
|
2006-12-19
|
|
Popularity:
|
4,978 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Hijacking DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | First Response 1.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-6475 CVE-2006-6476 CVE-2006-6477
|
|
Description: Some vulnerabilities have been reported in Mandiant First Response, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and manipulate data, and by malicious people to cause a DoS.
1) An error exists in the First Response agent (FRagent.exe) running in daemon mode, when certain exceptions are handled. This can be exploited to set the agent's socket to an indefinite CLOSE_WAIT state and therefore disable the service by sending specially crafted requests to an SSL enabled agent.
2) If a First Response agent (FRagent.exe) is bound to a 0.0.0.0 wildcard address ("all interfaces"), it is possible for a malicious process to hijack an agent and intercept connections by binding to the same port on a specific IP address. This can be exploited to cause a DoS (HTTP or SSL agent) or to manipulate response data sent to the client (HTTP agent).
This can further be exploited to send specially crafted HTTP responses that force the client to visit arbitrary URLs or download arbitrary content, but requires the use of HTTP (not the default setting).
The vulnerabilities are reported in versions prior to 1.1.1.
Solution: Update to version 1.1.1.
Provided and/or discovered by: Brian Reilly and Scott King
Original Advisory: http://www.symantec.com/enterprise/research/SYMSA-2006-013.txt
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|