|
Microsoft ISA Server 2000 Various Security Issues
|
|
Secunia Advisory:
|
SA11799
|
|
|
Release Date:
|
2004-06-10
|
|
Popularity:
|
9,491 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Security Bypass Exposure of system information Exposure of sensitive information DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Microsoft ISA Server 2000
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Microsoft has issued Service Pack 2 for ISA Server 2000. This includes patches for all previously reported vulnerabilities as well as older hot fixes, where some address potential security issues.
1) ICMP traffic is not blocked by the ISA Server 2000 while starting up, even though it has been restricted in the firewall policies. This allows malicious people to detect the presence of the system during a short period of time.
2) In certain cases, basic credentials may be sent over external HTTP connections even though this has been configured as SSL required. This may potentially disclose sensitive information to certain people, who are able to intercept the traffic.
3) The web proxy service may crash during the processing of HTTP redirect actions, when a content rule denies access.
4) Certain site and content rules can be bypassed when access to specific destinations are denied due to a canonicalization error. The problem is that a rule may not apply if a user requests an URL with a period (.) appended to the end.
Example:
http://www.restricted_site.com.
5) Under certain circumstances, a malformed SSL packet may crash the web proxy when "web publishing" a SSL web site.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|