Inktomi Corporation Information for VU#150227

HTTP proxy default configurations allow arbitrary TCP connections

Status

Not Affected

Vendor Statement

Inktomi Traffic Server allows CONNECT tunnels only to a list of specifically allowed target ports. CONNECT requests to any other port will be denied. The allowed port list can be read or updated from the "Protocols" page of the administrative GUI, or by editting the proxy .config.http.ssl_ports variable in the master configuration file. The only ports allowed by default are port 443 and port 563. Traffic Server blocks recursive service requests.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.