First published: Fri Feb 18 2011(Updated: )
F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI port.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
F-Secure Internet GateKeeper for Windows | =3.02.1221 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-0453 is considered to be medium due to the potential exposure of sensitive information.
To fix CVE-2011-0453, upgrade your F-Secure Internet Gatekeeper for Linux to version 3.03 or later.
CVE-2011-0453 allows remote attackers to obtain potentially sensitive information by accessing the system without authentication.
F-Secure Internet Gatekeeper for Linux versions 3.x before 3.03 are affected by CVE-2011-0453.
CVE-2011-0453 allows unauthorized access to the application’s access logs, which may contain sensitive information.