First published: Wed Mar 24 2010(Updated: )
Integer overflow in OmniWeb allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OmniWeb |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1102 has a medium severity rating due to its ability to bypass port restrictions.
To fix CVE-2010-1102, upgrade to the latest version of OmniWeb that includes the security patch.
The impact of CVE-2010-1102 allows remote attackers to initiate outbound TCP connections on restricted ports.
CVE-2010-1102 affects all versions of OmniWeb prior to the patch that addresses this vulnerability.
CVE-2010-1102 exploits an integer overflow by accepting a port number greater than the maximum value of the unsigned short data type.