Firewall Wizards mailing list archives

Re: Buffer Overruns


From: "Steven M. Bellovin" <smb () research att com>
Date: Fri, 17 Dec 1999 17:28:21 -0500

In message <385A1B90.E2213122 () home com>, Michael Kelly writes:
 I really feel silly asking this, but;
 Can these buffer overrun bugs penetrate firewalls? I'm trying to
convince the boss to ditch IE in favor of Netscape. (which is only
slightly better)


Yes, some buffer overruns can penetrate firewalls.

Fundamentally, firewalls cannot protect you against attacks at a higher level 
of the protocol stack than the firewall operates at.  If you allow http and 
html through your firewall, and there's a bug in the program at your end that 
processes the http and html -- yes, you're vulnerable.

This isn't a new issue; see, for example, CERT Advisory CA-98.10, CA-97.05, 
and many others.

                --Steve Bellovin




Current thread: