The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTTP header; (2) an invalid value in the Content-Length HTTP header, as demonstrated by a negative integer; or (3) a missing Content-Length HTTP header.
2008-12-11T15:30:00.440
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netwin | smsgate | ≤ 1.1n | Yes |
Application | netwin | smsgate | 1.0a | Yes |
Application | netwin | smsgate | 1.0c | Yes |
Application | netwin | smsgate | 1.0h | Yes |
Application | netwin | smsgate | 1.0r | Yes |
Application | netwin | smsgate | 1.0w | Yes |
Application | netwin | smsgate | 1.1m | Yes |