WinGate Invalid SMTP State Format String DoS
Medium Nessus Plugin ID 25879
SynopsisThe remote proxy is affected by a denial of service vulnerability.
DescriptionThe remote host appears to be running WinGate, a Windows application for managing and securing Internet access.
The version of WinGate installed on the remote host fails to sanitize user-supplied input to its SMTP server component of format strings before using it to log a problem. By connecting to the service and issuing commands the server was not expecting, a remote attacker may be able to force the service to an invalid state and crash the WinGate service itself, thereby denying service to legitimate users.
SolutionUpgrade to WinGate 6.2.2 or later.