PT-2005-3613 · Astaro · Astaro Security Linux
Oliver Karow
·
Publicado
2005-08-29
·
Atualizado
2017-07-11
·
CVE-2005-2730
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Astaro Security Linux version 6.0
Description
The issue allows remote attackers to obtain sensitive information via an invalid request. This is achieved by revealing a Proxy-authorization string in an error message, which can be exploited to gain access to sensitive data.
Recommendations
For Astaro Security Linux version 6.0, consider restricting access to the HTTP proxy to minimize the risk of exploitation until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Astaro Security Linux