SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Webwasher Denial of Service Vulnerability


Arrow  SecurityAlert : 3811
Arrow  CVE : CVE-2008-1797
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Exploit Available : No
Arrow  Credit : National Australia Bank Security
Arrow  Published : 16.04.2008

Arrow  Affected Software : Secure Computing Webwasher 6.6.3 build 3102 and older versions running on
CGLinux 4/5, RHEL 4, Debian 4, SLES10



Arrow  Advisory Content :  

Credit: The disclosure of this issue has been credited to National
Australia Bank Security

Assurance.

Vulnerable:

Secure Computing Webwasher 6.6.3 build 3102 and older versions running on
CGLinux 4/5, RHEL 4, Debian 4, SLES10

Not vulnerable:

Secure Computing Webwasher Builds 3150 and newer (all platforms)

Webwasher (all versions) for Windows

Webwasher (all versions) for Solaris

Webwasher (all versions) for some Linux (RHEL 3, SLES8, SLES9, Debian 3)

Webwasher 5.3 appliances (running CGLinux 3.x)

DISCUSSION

Due to a change in the behavior of newer Linux systems, we have become
aware that a Denial of Service attack can be launched against Webwasher
running on Linux based operating systems which will freeze the Webwasher
service. If this happens, Webwasher becomes unable to handle any request
until the Webwasher service is restarted.

The attack can be initiated by an internal user sending a specially crafted
URL to Webwasher. It could also be exploited by an external attacker by
redirecting proxy users to the exploit URL.

Who is affected?

Users of all Webwasher appliances version 6.x (CGLinux 4 or 5):

?If not running current version of Webwasher software but build numbers
prior to 3150

Users of Webwasher software versions

?If running on RedHat Enterprise Linux 4, Debian Linux 4 or Linux Suse
Linue 10

?And if not running current version of Webwasher software but build numbers
prior to 3150

Who is not affected?

?All Webwasher installations on current versions ? build numbers 3150 or
newer

?Webwasher Software customers on Windows, Solaris, Linux RedHat Enterprise
3, Linux Suse 8 and 9, Debian 3.1 and Webwasher appliances running with
CGLinux 3.x are not affected.

EXPLOIT

A special handcrafted URL has to be sent to Webwasher on the affected Linux
systems which will then freeze the application.

National Australia Bank Security Assurance has provided an undisclosed
proof of concept.

SOLUTION

The vendor has released Webwasher versions to address this:

?Webwasher 6.6.3 build 3150

?Webwasher 5.3.0 build 3159

Both are available at:
https://extranet.webwasher.com/download/csm/index.html

Webwasher appliances can be upgraded automatically via the GUI






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libopie __readrec() off-by-one

Security Risk Medium- 2010-04-23

This advisory is related to new FreeBSD advisory FreeBSD-SA-10:05.opie.

Apache RSS Apache Alert

» Apache ActiveMQ 5.4.0
   source code disclosure
   vulnerability

» Apache ActiveMQ 5.3.0
   Persistent Cross-Site
   Scripting

» Apache CouchDB 0.10.1
   Timing Attack
   Vulnerability

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.