CVE-2006-2341
Summary
| CVE | CVE-2006-2341 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-12 01:02:00 UTC |
| Updated | 2018-10-18 16:39:00 UTC |
| Description | The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Symantec | Enterprise Firewall | 8.0 | All | All | All |
| Application | Symantec | Enterprise Firewall | 8.0 | All | All | All |
| Application | Symantec | Gateway Security | 2.0.1 | All | All | All |
| Application | Symantec | Gateway Security | 3.0 | All | All | All |
| Hardware | Symantec | Gateway Security | 5000_series_2.0.1 | All | All | All |
| Hardware | Symantec | Gateway Security | 5000_series_3.0 | All | All | All |
| Application | Symantec | Gateway Security | 2.0.1 | All | All | All |
| Application | Symantec | Gateway Security | 3.0 | All | All | All |
| Hardware | Symantec | Gateway Security | 5000_series_2.0.1 | All | All | All |
| Hardware | Symantec | Gateway Security | 5000_series_3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Symantec Enterprise Firewall HTTP Proxy May Disclose Internal NAT Addresses | SECTRACK | securitytracker.com | Patch |
| Symantec Enterprise Firewall / Gateway Security HTTP Proxy Internal IP Leakage Weakness | BID | www.securityfocus.com | Exploit |
| Symantec Enterprise Firewall NAT/HTTP Proxy internal IP leakage | CONFIRM | securityresponse.symantec.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Symantec Firewall Products Internal IP Addresses Disclosure - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Symantec Gateway Security HTTP Proxy May Disclose Internal NAT Addresses | SECTRACK | securitytracker.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.