CVE-2004-0498: Medium severity Stonesoft firewall engine vulnerability
Published Dec 31, 2004
·Updated
The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.
Affected Software
1 affected component
Stonesoft firewall engine<=2.2.8
Event History
Dec 31, 2004
CVE Published
05:00 AM
Sep 1, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0498?
CVE-2004-0498 has a high severity level due to its potential to cause denial of service attacks.
2
Which versions of StoneSoft firewall engine are affected by CVE-2004-0498?
CVE-2004-0498 affects StoneSoft firewall engine version 2.2.8 and earlier.
3
How do I fix CVE-2004-0498?
To fix CVE-2004-0498, upgrade the StoneSoft firewall engine to a version that is newer than 2.2.8.
4
What type of attack does CVE-2004-0498 enable?
CVE-2004-0498 allows attackers to perform denial of service attacks by crashing the firewall through crafted H.323 packets.
5
Is there a workaround for CVE-2004-0498 if I cannot upgrade?
The best workaround for CVE-2004-0498 is to block H.323 traffic until you can upgrade to a patched version.