Denial of Service in Sygate Secure Enterprise
A Denial of Service (DoS) condition exists in Sygate Secure Enterprise 3.5 and earlier.
Ken Pfeil
August 12, 2004
1 Min Read
Reported August 11, 2004, byCorsaire Limited.
VERSIONS AFFECTED
DESCRIPTION
A Denial of Service (DoS) condition exists in SygateSecure Enterprise 3.5 and earlier. Sygate Secure Enterprise uses HTTP tocommunicate with the Sygate Security Agent clients. These exchanges don'timplement any form of replay protection, so an attacker can simply sendrepeated requests until all the resources on the host are exhausted.
VENDOR RESPONSE
The vendor, Sygate, has released a fix—3.5MR3—forthis problem.
CREDIT
Discovered by Martin O'Neal.
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like