Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11262
HistoryFeb 01, 2006 - 12:00 a.m.

[SA18622] Blue Coat ProxySG SGOS Two Security Issues

2006-02-0100:00:00
vulners.com
22

TITLE:
Blue Coat ProxySG SGOS Two Security Issues

SECUNIA ADVISORY ID:
SA18622

VERIFY ADVISORY:
http://secunia.com/advisories/18622/

CRITICAL:
Less critical

IMPACT:
Security Bypass

WHERE:
>From remote

OPERATING SYSTEM:
Blue Coat Security Gateway OS (SGOS) 4.x
http://secunia.com/product/5419/

DESCRIPTION:
Dominique GREGOIRE has reported two security issues in Blue Coat
ProxySG, which can be exploited by malicious people to bypass certain
security restrictions.

1) The HTTP proxy does not properly enforce port number restrictions
on the CONNECT method when content inspection rules are defined in a
policy. This allows the CONNECT method to be used to connect to
arbitrary ports.

2) An error in the handling of policy evaluation order causes rules
in the VPM (Visual Policy Manager) policy to be evaluated first,
followed by the Local file policy, and then the Central file policy,
regardless of the configured evaluation order.

The security issues have been reported in Bluecoat ProxySG running
SGOS version 4.1.2.1. Other versions may also be affected.

SOLUTION:
Add a rule to the VPM policy to disable the CONNECT method on all
ports except 443.

Rules that should be evaluated first should be added to the VPM
policy.

PROVIDED AND/OR DISCOVERED BY:
Dominique GREGOIRE

ORIGINAL ADVISORY:
http://www.secumind.net/content/french/modules/news/article.php?storyid=8


About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.