by adrien » Jun 09 06 7:31 pm
Hi All
We have released a fix today. The problem was related to the DNS resolver, not the WWW proxy. It was discovered in the WWW proxy using requests containing extremely large hostnames, however large hostnames are also able to be submitted potentially with other services, including the POP3, Telnet, and (unconfirmed - pre-processing reduces vulnerability here) SMTP server.
The DNS resolver has been in WinGate since 5.0, so we recommend anyone using WinGate version 5.0 or later upgrade to 6.1.3 as soon as possible.
Regards
Adrien