Vulnerability Description
The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Astaro | Security Linux | 6.001 |
References
- http://marc.info/?l=bugtraq&m=112501186602731&w=2
- http://secunia.com/advisories/16578/Vendor Advisory
- http://www.securityfocus.com/bid/14665
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22021
- http://marc.info/?l=bugtraq&m=112501186602731&w=2
- http://secunia.com/advisories/16578/Vendor Advisory
- http://www.securityfocus.com/bid/14665
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22021
FAQ
What is CVE-2005-2729?
CVE-2005-2729 is a vulnerability with a CVSS score of 7.5 (HIGH). The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services.
How severe is CVE-2005-2729?
CVE-2005-2729 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2729?
Check the references section above for vendor advisories and patch information. Affected products include: Astaro Security Linux.