-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2015.0020
 Resolved issue that could lead to Denial of Service on Barracuda Firewall
                               2 March 2015

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Barracuda Firewall
Operating System:     Network Appliance
Impact/Access:        Denial of Service -- Remote/Unauthenticated
Resolution:           Patch/Upgrade
Member content until: Wednesday, April  1 2015

OVERVIEW

        A vulnerability has been reported in Barracuda Firewall Release 
        6.6.x. [1]


IMPACT

        Barracuda has provided the following details regarding the 
        vulnerability:
        
        "On February 26th, 2015, Barracuda Networks released security 
        definition 2.1.16026 which resolves an issue where an attacker could
        perform a Denial of Service against Barracuda Firewall Release 
        6.6.x." [1]


MITIGATION

        Barracuda advises customers to update security definitions to 
        v2.1.16026 immediately. [1]


REFERENCES

        [1] Resolved issue that could lead to Denial of Service on Barracuda
            Firewall
            https://www.barracuda.com/SUPPORT/TECHALERTS#58

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBVPPe9xLndAQH1ShLAQIfVw/+PbUQhs7/86qKAN2BWjj8p5U8FjSI73ss
/xx2t9sDEYCbE54fj14lXJ0jilaARrAGJBtoB2HAVFP+WB5zm7Z5rwCT9DmgrNv+
xwbdt7LlF1EIhLQImVRoiYZVyyETlm+/XyuNxX0Re44RREgbT8YdsSxpb7yX5UG7
tYqqglqe3r2pd/U3tTEuKZauEjUzyDDGe3PLxlmGcIRJDVMFwI9R8E1On65kDVs1
Veafb0Xb0pktsZRHnHh0DSh95BfrXtxYGg8BC2zF5CsrqBFUkct3/Vg11h6hJjjX
4ZEHH2Wo/VbQtM7c3Qb75zmvX3PN9a2OJonmbIkhl67357s18kHaXV6unz2yblHH
k9uwR3hYWtlGt0F1wI/a0n7N/DyuVyoXRqKt8ipL6JOtF0GtyNzsnZHpdJzXgsl3
rg5VNR8SdutImy0h15Jz4uF2rn7auk2mg/ROu3IFKNCQSKWUSjuk+4TBuKW08JAG
KBeFGz8x4ET/pbZ7E+z3doWmeeykcbz3emzSw/JF8MycV/MH8/w+gnvNptOh1kRh
BGRwvCCsYvM5TZ5XxENOmp4yQzsVbIqBiM/FP1hgAOAMSxHhhzvpFkt2DZKi8Ir/
KQvmYojW9uAO2iMmeXjwKrbMwJ9zjTpmML/GzIQiULIn91BdBjHTN9sVTBg7vGU8
ucW5acbvZts=
=dV1E
-----END PGP SIGNATURE-----