Description
Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276. Bitdefender GravityZone versions prior to 26.4-1. Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.1.111.
Published: 2022-04-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

An automatic update to the following product version fixes the issues: Bitdefender Update Server version3.4.0.276. Bitdefender GravityZone version 26.4-1. Bitdefender Endpoint Security Tools for Linux version 6.2.21.171. Bitdefender Endpoint Security Tools for Windows version 7.4.1.111.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-15763 Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint Security Tools (in relay role), GravityZone (in Update Server role) allows an attacker to cause a Denial-of-Service. This issue affects: Bitdefender Update Server versions prior to 3.4.0.276. Bitdefender GravityZone versions prior to 26.4-1. Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.171. Bitdefender Endpoint Security Tools for Windows versions prior to 7.4.1.111.
History

No history.

Subscriptions

Bitdefender Endpoint Security Tools Gravityzone Update Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published:

Updated: 2024-09-16T22:02:25.418Z

Reserved: 2022-02-18T00:00:00.000Z

Link: CVE-2022-0677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-07T19:15:07.960

Modified: 2024-11-21T06:39:09.980

Link: CVE-2022-0677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses