PT-2005-3612 · Astaro · Astaro Security Linux

Oliver Karow

·

Published

2005-08-29

·

Updated

2017-07-11

·

CVE-2005-2729

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Astaro Security Linux version 6.0
Description The issue concerns the HTTP proxy in Astaro Security Linux, which fails to properly filter HTTP CONNECT requests to localhost. This allows remote attackers to bypass firewall rules and connect to local services.
Recommendations For Astaro Security Linux version 6.0, consider restricting access to the HTTP proxy or implementing additional firewall rules to minimize the risk of exploitation. As a temporary workaround, restrict access to local services to prevent unauthorized connections. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2729

Affected Products

Astaro Security Linux