CVE-2017-1000479
Summary
| CVE | CVE-2017-1000479 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-03 18:29:00 UTC |
| Updated | 2019-05-30 14:57:00 UTC |
| Description | pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Netgate | Pfsense | All | All | All | All |
| Application | Opnsense Project | Opnsense | All | All | All | All |
| Application | Opnsense Project | Opnsense | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Clickjacking vulnerability in CSRF error page pfSense - Security Advisories and Insights - Securify B.V. | MISC | www.securify.nl | Exploit, Third Party Advisory |
| pfSense 2.4.2-RELEASE-p1 and 2.3.5-RELEASE-p1 now available | MISC | www.netgate.com | Third Party Advisory |
| csrf: tighten csrf code paths a little · opnsense/core@d218b22 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| oss-security - Clickjacking vulnerability in CSRF error page pfSense | MLIST | www.openwall.com | Exploit, Mailing List, Third Party Advisory |
| Prevent Clickjacking in CSRF error page · pfsense/pfsense@386d89b · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Releases — 2.4.2 New Features and Changes | pfSense Documentation | MISC | doc.pfsense.org | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.