PT-2014-6061 · Netgate+1 · Pfsense+1

Publicado

2014-07-02

·

Atualizado

2019-05-30

·

CVE-2014-4695

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions pfSense versions prior to 2.1.4 Snort versions prior to 3.0.13
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This can be achieved via the referer parameter to "snort rules flowbits.php" or the returl parameter to "snort select alias.php".
Recommendations For Snort versions prior to 3.0.13, update to version 3.0.13 or later. For pfSense versions prior to 2.1.4, update to version 2.1.4 or later. As a temporary workaround, consider restricting access to the "snort rules flowbits.php" and "snort select alias.php" scripts until a patch is available. Avoid using the referer and returl parameters in the affected scripts until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2014-4695

Produtos afetados

Snort
Pfsense