![]() |
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ....
|
Guardian Digital Inc. > InfoCenter > Mailing List Archives > BugTraq BugTraq Mailing List Archive
From: Secure Computer Group (scg@udc.es)
______________________________________________________________________
Secure Computer Group - University of A Coruna
-- x --
dotpi.com Information Technologies Research Labs
______________________________________________________________________
ID: #20041214-1
Coordinated release date: 2004/12/14
CVE Name: CAN-2004-1022
Other references: N/A
Summary:
Impact: Insecure Credential Storage
Vendor: Kerio Technologies Inc.
Affected software: Kerio WinRoute Firewall (all versions)
Updates/Patches: Yes (see below)
General Information:
1. Executive summary:
As a result of its collaboration relationship the Secure Computer
KWF, KSF and KMS user credential database system uses symmetric
Anyone with a cyphertext of this database (that is, with access to
New versions of the software solve this and other minor problems
2. Technical details:
Following the latest trends and approaches to responsible
Full details will be published on 2005/03/14. This three month
3. Risk Assessment factors:
The attacker needs access to the user database, which is not
Despite this, special care should be taken on shared environments
It is also important to note that this could be an important
4. Solutions and recommendations:
Upgrade to the latest versions:
o Kerio Winroute Firewall 6.0.9
o Kerio ServerFirewall 1.0.1
o Kerio MailServer 6.0.5
As in any other case, follow, as much as possible, the Industry
Note:
Kerio Winroute Firewall 6.0.7 fixed CAN-2004-1022. Kerio Winroute
5. Common Vulnerabilities and Exposures (CVE) project:
The Common Vulnerabilities and Exposures (CVE) project has
______________________________________________________________________
Acknowledgements:
1. Special thanks to Vladimir Toncar and Pavel Dobry and the whole
3. The whole Research Lab at dotpi.com and specially to Carlos Veira
3. Secure Computer Group at University of A Coruna (scg at udc.es),
______________________________________________________________________
Credits:
Javier Munoz (Secure Computer Group) is credited with this discovery.
______________________________________________________________________
Related Links:
[1] Kerio Technologies Inc.
[2] Kerio WinRoute Firewall Downloads & Updates
[3] Kerio ServerFirewall Downloads & Updates
[4] Kerio MailServer Downloads & Updates
[5] Secure Computer Group. University of A Coruna
[6] Secure Computer Group. Updated advisory
[7] dotpi.com Information Technologies S.L.
[8] dotpi.com Research Labs
______________________________________________________________________
Legal notice:
Copyright (c) 2002-2004 Secure Computer Group. University of A Coruna
Permission is granted for the redistribution of this alert
If you wish to reprint the whole or any part of this alert in any
Disclaimer: The information in the advisory is believed to be
There are no warranties with regard to this information. Neither the
|