Symantec (Blue Coat) Reporter Denial of Service vulnerability (SYMSA1280)
Medium Nessus Plugin ID 125357
SynopsisThe remote host is running a version of Symantec (Blue Coat) Reporter that is affected by a Denial of Service vulnerability.
DescriptionAccording to its self-reported version number, the Symantec (formerly Blue Coat) Reporter installation running on the remote host is prior to 10.3.1.1. It is, therefore, is affected by a denial of service vulnerability. The SSL/TLS implementation on the remote host allows clients to renegotiate connections. The computational requirements forrenegotiating a connection are asymmetrical between the client and the server, with the server performing several times more work. Since the remote host does not appear to limit the number of renegotiations for a single TLS / SSL connection, this permits a client to open several simultaneous connections and repeatedly renegotiate them, possibly leading to a denial of service condition.
Note that Nessus has not attempted to exploit these issues but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Symantec Reporter version 10.3.1.1 or later.