|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Zone Alarm Pro contains a flaw that may allow a local denial of service. The issue is due to Zone Alarm Pro setting the configuration file/folder permissions for %windir%\Internet Logs\* to Everyone:Full Control. This allows any local user to make changes to the Zone Alarm configuration file. While the changes to the configuration are not processed by the server, the changes to the file trigger it's built in protection to prevent running with untrusted options and causes the firewall to shut down.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Available
Disclosure:
OSVDB Verified,
Vendor Disputed
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Zone Alarm Pro
 |
1.x |
2.x |
3.x |
5.0 |
4.x |
5.1 |
|
|
|
|
Credit |
- bipin gautam - visitbipin
yahoo.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|