First published: Fri Oct 03 2008(Updated: )
The CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via crafted HTTP headers, related to the "error handling mechanism."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan Corporate Edition | =8.0-sp1_patch1 | |
Trend Micro OfficeScan Corporate Edition | =8.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4403 is considered a medium severity vulnerability due to its potential for denial of service.
To fix CVE-2008-4403, you should update Trend Micro OfficeScan to build 2439 or later for 8.0 SP1 and apply Patch 1.
CVE-2008-4403 affects Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087.
CVE-2008-4403 involves a denial of service attack through crafted HTTP headers causing a NULL pointer dereference.
CVE-2008-4403 was publicly disclosed in 2008.