Vulnerability Description
GlowWorm FW before 1.5.3b4 allows remote attackers to cause a denial of service (kernel panic) via certain DNS responses that trigger infinite recursion in TrueDNS packet parsing, as originally observed with certain login.yahoo.com responses.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glowworm | Glowworm | <= 1.5.3b3 |
References
- http://glowworm.us/history/release_1_5_3_b4.html
- http://osvdb.org/43597
- http://glowworm.us/history/release_1_5_3_b4.html
- http://osvdb.org/43597
FAQ
What is CVE-2007-1653?
CVE-2007-1653 is a vulnerability with a CVSS score of 7.8 (HIGH). GlowWorm FW before 1.5.3b4 allows remote attackers to cause a denial of service (kernel panic) via certain DNS responses that trigger infinite recursion in TrueDNS packet parsing, as originally observ...
How severe is CVE-2007-1653?
CVE-2007-1653 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-1653?
Check the references section above for vendor advisories and patch information. Affected products include: Glowworm Glowworm.