CVE-2002-0990: Medium severity Symantec Enterprise Firewall vulnerability
The web proxy component in Symantec Enterprise Firewall (SEF) 6.5.2 through 7.0, Raptor Firewall 6.5 and 6.5.3, VelociRaptor, and Symantec Gateway Security allow remote attackers to cause a denial of service (connection resource exhaustion) via multiple connection requests to domains whose DNS server is unresponsive or does not exist, which generates a long timeout.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0990?
CVE-2002-0990 has a high severity rating due to its potential to cause a denial of service through connection resource exhaustion.
How do I fix CVE-2002-0990?
To mitigate CVE-2002-0990, apply patches provided by Symantec for affected firewall and gateway security products.
What products are affected by CVE-2002-0990?
CVE-2002-0990 affects Symantec Enterprise Firewall, Raptor Firewall, VelociRaptor, and Symantec Gateway Security versions 6.5.2 through 7.0.
What type of attack does CVE-2002-0990 enable?
CVE-2002-0990 enables attackers to perform a denial of service attack by exhausting connection resources.
Is CVE-2002-0990 easily exploitable?
Yes, exploiting CVE-2002-0990 requires only the ability to send multiple connection requests to the vulnerable system.