Two Denial of Service Conditions in Tiny Personal Firewall 3.0 for Windows

Ken Pfeil

August 20, 2002

2 Min Read
ITPro Today logo in a gray background | ITPro Today



Reported August 20, 2002, by Aaron Tan Lu.



VERSIONAFFECTED

 

  • Tiny Personal Firewall 3.0 for Windows

DESCRIPTION

 

Two Denial of Service (DoS) conditions exist in Tiny Personal Firewall 3.0 for Windows. The first vulnerability affects the default installation and use of the activity-logger tab. If an attacker uses multiple SYN, UDP, Internet Control Message Protocol (ICMP), and TCP full Connect to scan the host's ports while the vulnerable user browses the host's Personal Firewall Agent module firewall Log tab, a system crash occurs, consuming 100 percent of the system's resources. The second DoS condition is similar to the first, but occurs in the HIGH Security setting when an attacker uses a spoofed source addressing the firewall’s IP address.

 

VENDORRESPONSE

 

Thevendor, Tiny Software, has been notified, but has not yet released a patch for this vulnerability.

 

CREDIT
Discovered by Aaron Tan Lu of NSSI Research Labs.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like