PT-2009-3402 · Smoothwall+3 · Smoothwall Smoothguardian+6

Robert Auger

·

Publicado

2009-03-04

·

Atualizado

2009-06-18

·

CVE-2009-0803

CVSS v2.0

5.4

Média

VetorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SmoothWall SmoothGuardian versions as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008
Description The issue allows remote attackers to bypass access controls for certain technologies, such as Flash, Java, and Silverlight, and possibly communicate with restricted intranet sites. This is achieved through a crafted web page that causes a client to send HTTP requests with a modified Host header.
Recommendations For SmoothWall SmoothGuardian versions as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, consider disabling transparent interception mode until a patch is available. Restrict access to the HTTP endpoint that uses the Host header to determine the remote endpoint to minimize the risk of exploitation. Avoid using the Host header to determine remote endpoints in HTTP requests until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0803

Produtos afetados

Flash
Java
Networkguardian
Schoolguardian 2008
Silverlight
Smoothwall Firewall
Smoothwall Smoothguardian