The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTTP header; (2) an invalid value in the Content-Length HTTP header, as demonstrated by a negative integer; or (3) a missing Content-Length HTTP header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Smsgate | Netwin | * | 1.1n (including) |
Smsgate | Netwin | 1.0a (including) | 1.0a (including) |
Smsgate | Netwin | 1.0c (including) | 1.0c (including) |
Smsgate | Netwin | 1.0h (including) | 1.0h (including) |
Smsgate | Netwin | 1.0r (including) | 1.0r (including) |
Smsgate | Netwin | 1.0w (including) | 1.0w (including) |
Smsgate | Netwin | 1.1m (including) | 1.1m (including) |