|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
DeleGate Information for VU#150227
| Date Notified: | |
| Date Updated: | |
| Statement Date: | |
| Status Summary: | Not Vulnerable |
Vendor StatementWhen DeleGate is running as a HTTP proxy server, it allows only port 443 and 564 as the destination port of the CONNECT method, by default. When DeleGate relays a request with a header, it removes malformed header fields like "RCPT To:..." for example (illegal space in this case). And when DeleGate is relaying to a non-HTTP but privileged port, it tries to detect greeting message from non-HTTP server before relaying a request to it. If the server returns non-HTTP response like "220 ready" within a specified time period, then the request is rejected without forwarded to the server. These mechanisms have been available since 1999 (after DeleGate version 6).Vendor InformationThe vendor has not provided us with any further information regarding this vulnerability.
AddendumPlease see the Access control section of the DeleGate manual.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |