The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Personal_firewall | Kerio | 4.0.6 (including) | 4.0.6 (including) |
Personal_firewall | Kerio | 4.0.7 (including) | 4.0.7 (including) |
Personal_firewall | Kerio | 4.0.8 (including) | 4.0.8 (including) |
Personal_firewall | Kerio | 4.0.9 (including) | 4.0.9 (including) |
Personal_firewall | Kerio | 4.0.10 (including) | 4.0.10 (including) |
Personal_firewall | Kerio | 4.0.16 (including) | 4.0.16 (including) |
Personal_firewall | Kerio | 4.1 (including) | 4.1 (including) |
Personal_firewall | Kerio | 4.1.1 (including) | 4.1.1 (including) |