|
 |
|
Webwasher URL Processing Denial of Service Vulnerability
|
|
|
|
|
Secunia Advisory:
|
SA29674
|
|
|
Release Date:
|
2008-04-04
|
|
Last Update:
|
2008-04-17
|
|
|
Critical:
|

Less critical
|
|
Impact:
|
DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Webwasher 6.x Webwasher CSM Suite 5.x WebWasher EE WebWasher PG
|
| | CVE reference: | CVE-2008-1797 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: A vulnerability has been reported in Webwasher, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the processing of URLs when running on newer Linux system. This can be exploited to freeze the service via a specially crafted URL.
The vulnerability is reported in the following products:
* Webwasher appliances 6.x (CGLinux 4 or 5) prior to build number 3150
* Webwasher software versions prior to versions 6.6.3 build 3150 or 5.3.0 build 3159 running on:
- RedHat Enterprise Linux 4
- Debian Linux 4
- SLES 10
Solution: Update to versions 6.6.3 build 3150 or 5.3.0 build 3159:
https://extranet.webwasher.com/download/csm/index.html
Provided and/or discovered by: The vendor credits National Australia Bank Security Assurance.
Changelog: 2008-04-17: Added CVE reference.
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|