SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#140470

Apple Mac OS X Server Admin fails to properly restrict users from using the proxy service

Overview

The Apple Mac OS X Server HTTP proxy service does not restrict access by default and may allow unintended remote users to use the service.

I. Description

Mac OS X Server includes a service to provide for HTTP proxying. The HTTP proxy service does not include any access restrictions in the default configuration. If no external restrictions, such as firewalls, are in place, this may allow unintended remote use of the HTTP proxy service.

II. Impact

Unauthenticated remote attackers may be able to use the HTTP proxy service running on the local machine. This may result in the attacker gaining the ability to access previously inaccessible network locations or to hide the true origin of their attack.

III. Solution

Apply An Update

Apple has addressed the issue in Security Update 2005-005.

As a workaround, other access restrictions such as firewalls may be used to restrict access to the HTTP proxy service.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer Inc.Vulnerable5-May-2005

References


http://docs.info.apple.com/article.html?artnum=301528
http://secunia.com/advisories/15227/

Credit

Thanks to Apple Product Security for reporting this vulnerability.

This document was written by Ken MacInnis.

Other Information

Date Public:2005-05-03
Date First Published:2005-05-09
Date Last Updated:2005-07-06
CERT Advisory: 
CVE-ID(s):CAN-2005-1340
NVD-ID(s):CAN-2005-1340
US-CERT Technical Alerts: 
Metric:6.88
Document Revision:4

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader