PT-2014-6061 · Netgate+1 · Pfsense+1
Published
2014-07-02
·
Updated
2019-05-30
·
CVE-2014-4695
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
pfSense versions prior to 2.1.4
Snort versions prior to 3.0.13
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This can be achieved via the
referer parameter to "snort rules flowbits.php" or the returl parameter to "snort select alias.php".Recommendations
For Snort versions prior to 3.0.13, update to version 3.0.13 or later.
For pfSense versions prior to 2.1.4, update to version 2.1.4 or later.
As a temporary workaround, consider restricting access to the "snort rules flowbits.php" and "snort select alias.php" scripts until a patch is available.
Avoid using the
referer and returl parameters in the affected scripts until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snort
Pfsense