CVE-2005-3058
Last modified
CVE-2005-3058 is a vulnerability of currently unknown severity. Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.. EPSS estimates a 3.10% chance of exploitation in the next 30 days.
Description
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers without violating RFC2616.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | <= 2.8_mr10 |
| Fortinet | Fortios | <= 3_beta |
| Fortinet | Fortigate | 2.8 |
References
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
- http://secunia.com/advisories/18844Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0539Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3058?
How severe is CVE-2005-3058?
How do I fix CVE-2005-3058?
Are you affected by CVE-2005-3058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
