First published: Sun Aug 26 2012(Updated: )
Blue Coat ProxySG 6.1 before SGOS 6.1.5.1 and 6.2 before SGOS 6.2.2.1 writes the secure heap to core images, which allows context-dependent attackers to obtain sensitive authentication information by leveraging read access to a downloaded core file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blue Coat ProxySG OS | =6.1.2.1 | |
Blue Coat ProxySG OS | =6.1.1.1 | |
Blue Coat ProxySG OS | =6.1.2 | |
Blue Coat ProxySG OS | =6.2.2 | |
Blue Coat ProxySG OS | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5126 is classified as a medium severity vulnerability due to the potential exposure of sensitive authentication information.
To mitigate CVE-2011-5126, upgrade to Blue Coat ProxySG SGOS version 6.1.5.1 or higher for 6.1 series or 6.2.2.1 or higher for 6.2 series.
CVE-2011-5126 can be exploited by context-dependent attackers who have read access to core files from the vulnerable Blue Coat ProxySG versions.
CVE-2011-5126 affects Blue Coat ProxySG versions prior to SGOS 6.1.5.1 and 6.2.2.1.
CVE-2011-5126 can expose sensitive authentication information that is stored in the secure heap when core images are written.