A vulnerability has been identified in Cisco PIX/ASA/FWSM, which could be exploited by attackers to bypass HTTP content restrictions. This flaw is due to an error within the handling of fragmented HTTP GET requests when the application is configured to use Websense/N2H2 for content filtering, which could be exploited by attackers to cause a vulnerable firewall to mistakenly allow a restricted web site to be accessed.
Credits
Vulnerability reported by George D. Gal
ChangeLog
2006-05-09 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.