发布时间 :2001-02-12 00:00:00
修订时间 :2017-10-09 21:29:21

[原文]Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.

[CNNVD]Watchguard SOHO防火墙超大GET请求DoS漏洞(CNNVD-200102-074)

        WatchGuard SOHO防火墙的HTTP服务器存在缓冲区溢出漏洞。远程攻击者借助超长GET请求导致服务拒绝和可能执行任意代码。

        Watchguard has addressed this vulnerability with the latest release of SOHO Firewall. The latest version can be downloaded at the following location:

WatchGuard Firebox SOHO GET Request Overflow DoS
Remote / Network Access Denial of Service, Input Manipulation
Loss of Integrity, Loss of Availability
Exploit Public

WatchGuard Firebox SOHO contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends an overly long GET request to the Web administration interface, and will result in loss of availability for the firewall.

- 时间线

2000-12-14 Unknow
2000-12-14 Unknow

- 解决方案

Upgrade to version 2.2.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Watchguard SOHO Firewall Oversized GET Request DoS Vulnerability
Failure to Handle Exceptional Conditions 2114
Yes Yes
2000-12-14 12:00:00 2009-07-11 04:46:00
Discovered by Steven Maks and Keith Jarvis of Internet Security Systems <> and posted to Bugtraq on December 14, 2000.

- 受影响的程序版本

WatchGuard SOHO Firewall 2.1.3
WatchGuard SOHO Firewall 1.6
WatchGuard SOHO Firewall 2.2.1

- 不受影响的程序版本

WatchGuard SOHO Firewall 2.2.1

- 漏洞讨论

SOHO Firewall is an appliance firewall by Watchguard Technologies Inc. designed for Small Office/Home Office users.

SOHO Firewall is susceptible to a trivial denial of service attack. Performing an overly long GET request to the web server component will cause SOHO Firewall to crash. Restarting the service is required in order to regain normal functionality. Watchguard has confirmed that this vulnerability could not be implemented to launch arbitrary code.

Successful exploitation of this vulnerability could assist in the development of further attacks due to the elimination of a firewall defense.

- 漏洞利用

See discussion.

- 解决方案

Watchguard has addressed this vulnerability with the latest release of SOHO Firewall. The latest version can be downloaded at the following location:

