First published: Sun Oct 13 2013(Updated: )
Race condition in the HTTP Deep Packet Inspection (DPI) feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.5), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.4), 9.0.x before 9.0(1.4), and 9.1.x before 9.1(1.2), in certain conditions involving the spoof-server option or ActiveX or Java response inspection, allows remote attackers to cause a denial of service (device reload) via a crafted HTTP response, aka Bug ID CSCud37992.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Adaptive Security Appliance Software | =8.2 | |
Cisco Adaptive Security Appliance Software | =8.2\(1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(2\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3\) | |
Cisco Adaptive Security Appliance Software | =8.2\(3.9\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.1\) | |
Cisco Adaptive Security Appliance Software | =8.2\(4.4\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5.35\) | |
Cisco Adaptive Security Appliance Software | =8.2\(5.38\) | |
Cisco Adaptive Security Appliance Software | =8.3\(1\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2.34\) | |
Cisco Adaptive Security Appliance Software | =8.3\(2.37\) | |
Cisco Adaptive Security Appliance Software | =8.4 | |
Cisco Adaptive Security Appliance Software | =8.4\(1\) | |
Cisco Adaptive Security Appliance Software | =8.4\(1.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2\) | |
Cisco Adaptive Security Appliance Software | =8.4\(2.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(3\) | |
Cisco Adaptive Security Appliance Software | =8.4\(4.11\) | |
Cisco Adaptive Security Appliance Software | =8.4\(5\) | |
Cisco Adaptive Security Appliance Software | =8.5 | |
Cisco Adaptive Security Appliance Software | =8.5\(1\) | |
Cisco Adaptive Security Appliance Software | =8.5\(1.17\) | |
Cisco Adaptive Security Appliance Software | =8.6 | |
Cisco Adaptive Security Appliance Software | =8.6\(1\) | |
Cisco Adaptive Security Appliance Software | =8.6\(1.3\) | |
Cisco Adaptive Security Appliance Software | =8.6\(1.10\) | |
Cisco Adaptive Security Appliance Software | =8.7\(1.3\) | |
Cisco Adaptive Security Appliance Software | =9.0 | |
Cisco Adaptive Security Appliance Software | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.