First published: Fri Dec 31 2004(Updated: )
The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Astaro Security Gateway | =4.020 | |
Sophos Astaro Security Gateway | =4.023 | |
Sophos Astaro Security Gateway | =4.022 | |
Sophos Astaro Security Gateway | =4.017 | |
Sophos Astaro Security Gateway | =4.019 | |
Sophos Astaro Security Gateway | =4.018 | |
Sophos Astaro Security Gateway | =4.021 |
http://www.astaro.org/showflat.php?Cat=&Number=51459&page=0&view=collapsed&sb=5&o=&fpart=1#51459
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2251 is considered to have a low severity level as it primarily exposes version information that may aid attackers.
To fix CVE-2004-2251, upgrade the Astaro Security Linux to a version later than 4.024, which resolves the vulnerability.
CVE-2004-2251 affects Astaro Security Linux versions 4.017 through 4.023.
CVE-2004-2251 allows attackers to craft more effective targeted attacks based on the disclosed version information of the PPTP server.
There are no documented workarounds for CVE-2004-2251; upgrading to a secure version is recommended.