Kerio heeft voor haar Personal Firewall een update uitgebracht waarin twee security bugs in hun remote administration system worden opgelost. Dit programma is een mooie firewall en is tevens gratis voor thuisgebruik. Het changelog ziet er als volgt uit:
*Vulnerability Description*
- fixed security bug (http://www.net-security.org/vuln.php?id=2649)
Kerio Personal Firewall (KPF) is a firewall for workstations designed to protect them against attacks from the Internet and the local network. We found two security vulnerabilities in KPF's remote administration system:
[BID 7179]
A replay attack is possible against the authenticated/encrypted channel for remote administration. A design problem in the authentication mechanism for remote administration allows an attacker to replay captured packets from a valid remote administration session in order to reproduce the administrator's directives to the personal firewall.
For example if the attacker is able to sniff a valid session in which the administrator disabled the firewall capabilities, then the attacker will gain the ability to disable the personal firewall at will at any time in the future.
[BID 7180]
A remotely exploitable buffer overflow exists in the administrator authentication process.
*Vulnerable Packages*
Kerio Personal Firewall version 2.1.4 and previous versions.[break]Voor nog meer informatie over de security bug klik je hier.