|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
FirePass contains a flaw that may allow a malicious user to bypass web filter restrictions. The issue is triggered when a user submits an IP address in a URL as a dotless, decimal value, which may allow to bypass any 'deny' statements that may have otherwise affected the IP address, resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
User of series 5 of the software should upgrade to version 5.5.2. There is also a feature release for verson 6 which addresses this issue. Users of 5.5.1 should contact the vendor for a hotfix. These measure have been reported to address this vulnerability.
|
|
Products |
|
FirePass
 |
5.0 |
5.5.1 |
6.0 |
5.5.2 |
5.4 |
5.2.1 |
|
|
|
|
Credit |
- Michael Ligh - mnin.org
- Greg Sinclair - gssincla
nnlsoftware.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|