![]() |
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ....
|
Guardian Digital Inc. > InfoCenter > Mailing List Archives > BugTraq BugTraq Mailing List Archive
From: Secure Computer Group (scg@udc.es)
______________________________________________________________________
Secure Computer Group - University of A Coruna
-- x --
dotpi.com Information Technologies Research Labs
______________________________________________________________________
ID: #20041214-2
Document revision: 1.0
Coordinated release date: 2004/12/14
CVE Name: CAN-2004-1023
Other references: N/A
Summary:
Impact: Privilege escalation
Rating/Severity: Low
Vendor: Kerio Technologies Inc.
Affected software: Kerio WinRoute Firewall (all versions)
Updates/Patches: Yes (see below)
General Information:
1. Executive summary:
As a result of its collaboration relationship the Secure Computer
Kerio WinRoute Firewall, Kerio ServerFirewall and Kerio MailServer
As a result, anyone belonging to the 'Power Users' system group
System administrators should enforce ACL security settings in
New versions of the software solve this an other minor problems
2. Technical details:
Following the latest trends and approaches to responsible
Full details will be published on 2005/03/14. This three month
3. Risk Assessment factors:
The attacker would need local interactive access to the
The most risky scenarios are the ones in which the server machine
Special care should be taken on such environments and every step
Privilege escalation, system and software tampering and the
4. Solutions and recommendations:
Enforce the file system ACLs and/or upgrade to the latest
o Kerio Winroute Firewall 6.0.9
o Kerio MailServer 6.0.5
As in any other case, follow, as much as possible, the Industry
5. Common Vulnerabilities and Exposures (CVE) project:
The Common Vulnerabilities and Exposures (CVE) project has
______________________________________________________________________
Acknowledgements:
1. Special thanks to Vladimir Toncar and Pavel Dobry and the whole
3. The whole Research Lab at dotpi.com and specially to Carlos Veira
3. Secure Computer Group at University of A Coruna (scg at udc.es),
______________________________________________________________________
Credits:
Javier Munoz (Secure Computer Group) is credited with this discovery.
______________________________________________________________________
Related Links:
[1] Kerio Technologies Inc.
[2] Kerio WinRoute Firewall Downloads & Updates
[3] Kerio ServerFirewall Downloads & Updates
[4] Kerio MailServer Downloads & Updates
[5] Secure Computer Group. University of A Coruna
[6] Secure Computer Group. Updated advisory
[7] dotpi.com Information Technologies S.L.
[8] dotpi.com Research Labs
______________________________________________________________________
Legal notice:
Copyright (c) 2002-2004 Secure Computer Group. University of A Coruna
Permission is granted for the redistribution of this alert
If you wish to reprint the whole or any part of this alert in any
Disclaimer: The information in the advisory is believed to be
There are no warranties with regard to this information. Neither the
|