PT-2014-6062 · Netgate+1 · Pfsense+1
Publicado
2014-07-02
·
Atualizado
2019-05-30
·
CVE-2014-4696
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Suricata versions prior to 1.0.6
pfSense versions prior to 2.1.4
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This can be achieved via the
referer parameter to "suricata rules flowbits.php" or the returl parameter to "suricata select alias.php".Recommendations
For Suricata versions prior to 1.0.6, update to version 1.0.6 or later.
For pfSense versions prior to 2.1.4, update to version 2.1.4 or later.
As a temporary workaround, consider restricting access to the "suricata rules flowbits.php" and "suricata select alias.php" scripts until a patch is available.
Avoid using the
referer and returl parameters in the affected scripts until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Suricata
Pfsense