Register | Forget Password | Login
Search :
SecurityReason

News

Search

SecurityAlert

About SecurityAlert

ExploitAlert

SecurityReason Research

WLB

WLB Database

Send to WLB

About WLB

RSS

News

SecurityAlert

World Laboratory of Bugtraq

ExploitAlert

Apache

PHP

Corporate

Contact

About us

Services

SecurePHP

Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Details : SecurityAlert

  Topic : Webwasher Denial of Service Vulnerability
  SecurityAlert : 3811
  CVE : CVE-2008-1797
  SecurityRisk : Medium  alert  (About)
  Remote Exploit : Yes
  Local Exploit : No
  Exploit Given : No
  Credit : National Australia Bank Security
  Published : 16.04.2008

  Affected Software : Secure Computing Webwasher 6.6.3 build 3102 and older versions running on
CGLinux 4/5, RHEL 4, Debian 4, SLES10



  Advisory Text :  

Credit: The disclosure of this issue has been credited to National
Australia Bank Security

Assurance.

Vulnerable:

Secure Computing Webwasher 6.6.3 build 3102 and older versions running on
CGLinux 4/5, RHEL 4, Debian 4, SLES10

Not vulnerable:

Secure Computing Webwasher Builds 3150 and newer (all platforms)

Webwasher (all versions) for Windows

Webwasher (all versions) for Solaris

Webwasher (all versions) for some Linux (RHEL 3, SLES8, SLES9, Debian 3)

Webwasher 5.3 appliances (running CGLinux 3.x)

DISCUSSION

Due to a change in the behavior of newer Linux systems, we have become
aware that a Denial of Service attack can be launched against Webwasher
running on Linux based operating systems which will freeze the Webwasher
service. If this happens, Webwasher becomes unable to handle any request
until the Webwasher service is restarted.

The attack can be initiated by an internal user sending a specially crafted
URL to Webwasher. It could also be exploited by an external attacker by
redirecting proxy users to the exploit URL.

Who is affected?

Users of all Webwasher appliances version 6.x (CGLinux 4 or 5):

?If not running current version of Webwasher software but build numbers
prior to 3150

Users of Webwasher software versions

?If running on RedHat Enterprise Linux 4, Debian Linux 4 or Linux Suse
Linue 10

?And if not running current version of Webwasher software but build numbers
prior to 3150

Who is not affected?

?All Webwasher installations on current versions ? build numbers 3150 or
newer

?Webwasher Software customers on Windows, Solaris, Linux RedHat Enterprise
3, Linux Suse 8 and 9, Debian 3.1 and Webwasher appliances running with
CGLinux 3.x are not affected.

EXPLOIT

A special handcrafted URL has to be sent to Webwasher on the affected Linux
systems which will then freeze the application.

National Australia Bank Security Assurance has provided an undisclosed
proof of concept.

SOLUTION

The vendor has released Webwasher versions to address this:

?Webwasher 6.6.3 build 3150

?Webwasher 5.3.0 build 3159

Both are available at:
https://extranet.webwasher.com/download/csm/index.html

Webwasher appliances can be upgraded automatically via the GUI





  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

*BSD libc (strfmon) Multiple vulnerabilities

high- 2008-03-25

Maksymilian Arciemowicz discovered a Integer Overflow vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.

Apache rss

» Apache Tomcat <=
   6.0.18 UTF8 Directory
   Traversal Vulnerability

» Apache Tomcat information
   disclosure vulnerability

» Apache Tomcat XSS
   vulnerability

» Apache-SSL memory
   disclosure

PHP rss

» PHP 5.2.6 chdir(),ftok()
   (standard ext) safe_mode
   bypass

» PHP 5.2.6 posix_access()
   (posix ext) safe_mode
   bypass

» PHP 5.2.5 and prior :
   *printf() functions
   Integer Overflow

» PHP 5.2.5 cURL safe_mode
   bypass

Copyright © SecurityReason. All Rights Reserved.