vendor:
Internet Gatekeeper
by:
Kevin Joensen
7.5
CVSS
HIGH
Heap Overflow
122
CWE
Product Name: Internet Gatekeeper
Affected Version From: 5.40
Affected Version To: 5.40
Patch Exists: YES
Related CWE: N/A
CPE: a:f-secure:internet_gatekeeper
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
F-Secure Internet Gatekeeper 5.40 – Heap Overflow (PoC)
This exploit is a proof-of-concept for a heap overflow vulnerability in F-Secure Internet Gatekeeper 5.40. The vulnerability is triggered by sending a specially crafted POST request with a large Content-Length header. This causes a heap overflow, which can be used to overwrite a fast bin chunk and gain code execution. The exploit was discovered by Kevin Joensen and detailed in a blog post by Doyensec.
Mitigation:
F-Secure has released a patch for this vulnerability. Users should update to the latest version of F-Secure Internet Gatekeeper to protect against this vulnerability.