PDA

View Full Version : Kerio Personal Firewall Vulnerability


kareldjag
April 1st, 2005, 03:09 AM
Hi,

A vulnerability has been found in Kerio rules:

http://www.frsirt.com/english/advisories/2005/0302

Regards

BlitzenZeus
April 1st, 2005, 07:26 AM
It doesn't exactly give anything other than a vague idea what can happen, also if this is just an os exploit like I'm thinking, and not an exploit in the firewall itself, then they are just making their sandboxing stronger as it would be an os exploit anyway.

I found a better link, 4.x is effected only...
http://www.osvdb.org/15123

kareldjag
April 1st, 2005, 10:06 AM
Hi,

Or this one: http://securitytracker.com/alerts/2005/Mar/1013607.html

In all cases, Kerio users have to be informed.

Regards

Diver
April 1st, 2005, 10:23 AM
eeeek, a leak!

zfactor
April 1st, 2005, 11:32 AM
they just released the version 4.1.3 which from what i understand was supposed to fix this problem. not 100% sure if it did but was supposed to

Kerodo
April 1st, 2005, 09:39 PM
-{ Quote: "eeeek, a leak!" }-

Yeah... funny how they don't mention it until they already have a fix.