Two vulnerabilities were identified in FortiGate, which could be exploited by remote attackers to bypass security policies.
The first issue is due to an error in the URL blocking functionality that fails to properly filter specially crafted HTTP requests terminated by the CR character instead of CRLF, or malformed HTTP/1.0 requests with no host header, which could be exploited by attackers to bypass security restrictions.
The second flaw is due to an error in the virus scanning functionality that fails to properly scan files sent over FTP under certain conditions.
Credits
Vulnerabilities reported by Mathieu Dessus
ChangeLog
2006-02-13 : Initial release
2006-02-26 : Updated Solution
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.