2015 m. lapkričio 6 d., penktadienis

Cisco Security Advisory: Cisco Web Security Appliance Cache Reply Denial of Service Vulnerability

Cisco Web Security Appliance Cache Reply Denial of Service Vulnerability

Advisory ID: cisco-sa-20151104-wsa1

Revision 1.0

For Public Release 2015 November 4 16:00 UTC (GMT)

+-----------------------------------------------------------
----------

Summary
=======

A vulnerability in the proxy cache functionality of Cisco AsyncOS for
Cisco Web Security Appliance (WSA) could allow an unauthenticated,
remote attacker to cause a denial of service (DoS) condition because
the device runs out of system memory.

The vulnerability is due to improper memory operations by the affected
software. The software fails to free a memory object when it retrieves
data from the proxy server cache to terminate a TCP connection. An
attacker could exploit this vulnerability by opening many proxy
connections through the WSA. An exploit could allow the attacker to
cause the WSA to stop passing traffic when enough memory is leaked.

Cisco has released software updates that address this vulnerability.
A workaround that mitigates this vulnerability is also available.

This advisory is available at the following link:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151104-wsa1

Komentarų nėra:

Rašyti komentarą