PT-2009-3402 · Smoothwall+3 · Smoothwall Smoothguardian+6
Robert Auger
·
Publicado
2009-03-04
·
Atualizado
2009-06-18
·
CVE-2009-0803
CVSS v2.0
5.4
Média
| Vetor | AV:N/AC:H/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SmoothWall SmoothGuardian versions as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008
Description
The issue allows remote attackers to bypass access controls for certain technologies, such as Flash, Java, and Silverlight, and possibly communicate with restricted intranet sites. This is achieved through a crafted web page that causes a client to send HTTP requests with a modified
Host header.Recommendations
For SmoothWall SmoothGuardian versions as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, consider disabling transparent interception mode until a patch is available. Restrict access to the HTTP endpoint that uses the
Host header to determine the remote endpoint to minimize the risk of exploitation. Avoid using the Host header to determine remote endpoints in HTTP requests until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Flash
Java
Networkguardian
Schoolguardian 2008
Silverlight
Smoothwall Firewall
Smoothwall Smoothguardian