Sign up for Barracuda Networks Tech Alerts
| Resolved vulnerability in the TLS/SSL protocol during session renegotiation in select Barracuda Networks products | |
| Date: | 2009-12-04 |
| Affected Products: | Barracuda IM Firewall Release 4.1 and earlier Barracuda Link Balancer Release 1.3.1.006 and earlier Barracuda Load Balancer Release 3.0 and earlier Barracuda Message Archiver Release 2.1.0.014 and earlier Barracuda Spam & Virus Firewall Release 4.0.1.009 and earlier Barracuda SSL VPN Release 1.5.0.028 and earlier Barracuda Web Application Firewall Release 7.3.1.007 and earlier Barracuda Web Filter Release 4.2.0.010 and earlier |
| Revision: | A1.0 |
| Risk Rating: | Low |
Recently, security researchers discovered an issue where arbitrary code could be injected into the beginning of a TLS/SSL session during key renegotiation by a remote attacker conducting a man-in-the-middle (MITM) attack. In order for code to be injected an attacker would need access to a network along the path of communication between the client and the server. Details of the vulnerability can be viewed here:
|
|
| Resolved input field validation issues associated with the Barracuda Console Configuration Tool in select Barracuda Networks products. | |
| Date: | 2009-08-14 |
| Affected Products: | Barracuda IM Firewall Release 3.4 (generally available: 2009-04-14) and earlier Barracuda Link Balancer Release 1.1.028 (generally available: 2009-03-17) and earlier Barracuda Load Balancer Release 2.5.011 (generally available: 2009-04-06) and earlier Barracuda Message Archiver Release 1.1.0.010 (generally available: 2008-03-03) and earlier Barracuda Spam & Virus Firewall Release 3.5.12.012 (generally available: 2009-04-14) and earlier Barracuda SSL VPN Release 1.2.6.004 (generally available: 2009-03-11) and earlier Barracuda Web Application Firewall Release 7.2.2.005 (generally available: 2009-05-05) and earlier Barracuda Web Filter Release 4.1.0.013 (generally available: 2009-04-16) and earlier |
| Revision: | A1.0 |
| Risk Rating: | Low |
Recently, security researcher Jon Oberheide (jon@oberheide.org) discovered and worked with Barracuda Networks to resolve a field input validation issue in the Barracuda Console Configuration Tool. Reproducing the issue requires physical access to the Barracuda Networks appliance itself through physical keyboard and monitor connections. The issue does not apply to any access over networking protocols. Barracuda Networks resolved this issue identified by Jon Oberheide (jon@oberheide.org) by making generally available firmware releases for the following products and issuing a security definition 2.0.1 (2009-08-14):
For maximum protection, Barracuda Networks recommends that all customers upgrade to the latest generally available release of the firmware and ensure that security definitions are set to On. |
|
Barracuda Backup Login






