CVE-2002-2294: Buffer Overflow
Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed RealAudio (rad) packets that are not properly handled by the RealAudio Proxy, or (2) crafted packets to the statistics service (statsd).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2294?
CVE-2002-2294 has a high severity rating due to the potential for denial of service attacks.
How do I fix CVE-2002-2294?
To mitigate CVE-2002-2294, upgrade to the latest version of the affected software, ensuring you apply all relevant patches.
Which products are affected by CVE-2002-2294?
CVE-2002-2294 affects multiple versions of Symantec Raptor Firewall, Enterprise Firewall, VelociRaptor, and Gateway Security products.
What kind of attack can be executed using CVE-2002-2294?
An attacker can exploit CVE-2002-2294 by sending malformed RealAudio packets to trigger buffer overflows, resulting in service terminations.
Is there a workaround for CVE-2002-2294?
The best workaround for CVE-2002-2294 is to restrict access to the affected ports and implement network segmentation until a patch is applied.