Description
|
|
Two vulnerabilities have been identified in Ingate Firewall and Ingate SIParator, which could be exploited by attackers to cause a denial of service or execute arbitrary scripting code.
The first issue is due to errors in the SIP module and the web server that do not properly handle a specially crafted SSL/TLS handshake (when SSL/TLS is enabled), which could be exploited by remote attackers to crash or restart a vulnerable application.
The second flaw is due to an input validation error in the GUI that does not validate certain parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the administrator's browser in the security context of an affected Web site.
|