PT-2014-6062 · Netgate+1 · Pfsense+1

Published

2014-07-02

·

Updated

2019-05-30

·

CVE-2014-4696

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 1.0.6 pfSense versions prior to 2.1.4
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This can be achieved via the referer parameter to "suricata rules flowbits.php" or the returl parameter to "suricata select alias.php".
Recommendations For Suricata versions prior to 1.0.6, update to version 1.0.6 or later. For pfSense versions prior to 2.1.4, update to version 2.1.4 or later. As a temporary workaround, consider restricting access to the "suricata rules flowbits.php" and "suricata select alias.php" scripts until a patch is available. Avoid using the referer and returl parameters in the affected scripts until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-4696

Affected Products

Suricata
Pfsense