Finjan SurfinGate file name security bypass

finjan-surfingate-security-bypass (21010) The risk level is classified as HighHigh Risk

Description:

Finjan SurfinGate could allow a remote attacker to bypass security restrictions caused by a vulnerability with URL-encoded file names being improperly blocked. If the malicious file is not blocked based upon the Content-Type HTTP header, a remote attacker could send a specially-crafted request to bypass the blocking of various file types.


Consequences:

Bypass Security

Remedy:

No remedy available as of July 9, 2011.

References:

  • Finjan Web site: Finjan Software.
  • BID-13959: Finjan SurfinGate ASCII File Extension File Filter Circumvention Vulnerability
  • CVE-2005-1994: Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using %2e.
  • SA15711: Finjan SurfinGate URL Encoded URL Filtering Bypass
  • VUPEN/ADV-2005-0778: Finjan SurfinGate ASCII File Extension Security Bypass Issue

Platforms Affected:

  • Finjan Finjan SurfinGate 7.0 SP3
  • Finjan Finjan SurfinGate 7.0 SP2

Reported:

Jun 15, 2005

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page