PT-2005-3889 · Fortinet · Fortigate
Published
2005-12-31
·
Updated
2018-10-19
·
CVE-2005-3058
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiGate version 2.8
Description
The issue is related to an interpretation conflict that allows remote attackers to bypass the URL blocker. This can be achieved through an HTTP request that is terminated with a line feed (LF) and not a carriage return line feed (CRLF), or through an HTTP request with no Host field, which most web servers can process without violating RFC2616.
Recommendations
For Fortinet FortiGate version 2.8, consider updating to a version that addresses this issue, or as a temporary workaround, restrict access to the URL blocker to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortigate