PT-2005-3889 · Fortinet · Fortigate

Published

2005-12-31

·

Updated

2018-10-19

·

CVE-2005-3058

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Fortinet FortiGate version 2.8
Description The issue is related to an interpretation conflict that allows remote attackers to bypass the URL blocker. This can be achieved through an HTTP request that is terminated with a line feed (LF) and not a carriage return line feed (CRLF), or through an HTTP request with no Host field, which most web servers can process without violating RFC2616.
Recommendations For Fortinet FortiGate version 2.8, consider updating to a version that addresses this issue, or as a temporary workaround, restrict access to the URL blocker to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-3058

Affected Products

Fortigate