This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Kerio updates/advisories

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Kerio Control v7.1.0 released
- http://secunia.com/advisories/42388/
Release Date: 2010-11-30
Criticality level: Moderately critical
Impact: Unknown
Where: From remote
Solution Status: Vendor Patch
Software: Kerio Control 7.x
… vulnerability is reported in versions prior to 7.1.0.
Solution: Update to version 7.1.0.
Original Advisory:
http://www.kerio.com/control/history
(formerly Kerio WinRoute Firewall)
Version 7.1.0 - November 30, 2010

:ph34r:
FYI…

Kerio Firewall vuln - patch available
- http://www.securitytracker.com/id?1024913
Dec 20 2010
Solution: The vendor has issued a fix (7.1.0 Patch 1).
The vendor's advisory is available* …
* http://www.kerio.com/support/security-advisories#1012
Date: December 20, 2010
Severity: High
Name: HTTP cache poisoning vulnerability
Affected products: Kerio WinRoute Firewall all versions, Kerio Control up to version 7.1.0
Fix availability: The following product versions are not vulnerable: Kerio Control version 7.1.0 Patch 1 and higher.
Description: By sending a specially crafted HTTP data over a non-HTTP TCP connection a malicious web site could trick the HTTP cache to store arbitrary data. That data would then be served to clients instead of the legitimate content.
Mitigation factors: HTTP cache is disabled by default. It must be enabled in order for this attack to succeed.
Workaround: Disable HTTP cache…
> http://www.kerio.com/node/588
Release history

:ph34r: