|
|
Info |
Last Modified |
| 9 months ago |
|
|
|
|
Description |
Barracuda Spam Firewall contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an end user interacts with the system, which may disclose the user's encoded password in the URL. The encoded password is transmitted without the protection of SSL encryption, but would require an attacker to sniff the connection to obtain the information.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Cryptographic,
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Concern
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Barracuda Spam Firewall
 |
3.1.17 |
|
|
|
|
Credit |
- security curmudgeon - jericho
attrition.org - attrition.org
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|