Denial of Service in Sygate Secure Enterprise

A Denial of Service (DoS) condition exists in Sygate Secure Enterprise 3.5 and earlier.

Ken Pfeil

August 12, 2004

1 Min Read
ITPro Today logo

Reported August 11, 2004, byCorsaire Limited.
 

VERSIONS AFFECTED

DESCRIPTION
A Denial of Service (DoS) condition exists in SygateSecure Enterprise 3.5 and earlier. Sygate Secure Enterprise uses HTTP tocommunicate with the Sygate Security Agent clients. These exchanges don'timplement any form of replay protection, so an attacker can simply sendrepeated requests until all the resources on the host are exhausted.
 

VENDOR RESPONSE
The vendor, Sygate, has released a fix—3.5MR3—forthis problem.

CREDIT
Discovered by Martin O'Neal.

 

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like