Advanced IT-Security, a Scandinavian security consultancy, notified Symantec of a denial-of-service (D0S) issue they had discovered with the web proxy component in the Symantec Enterprise Firewall. A malicious user who is able to establish a remote connection to the proxy server could, by requesting multiple connections to a non-existent or erroneous internal URL, cause the proxy server to timeout for an extended period of time. While timed out, the server fails to process any subsequent connection requests
Thanks for your feedback. Let us know if you have additional comments below. (requires login)