Bug#540862: apache2: xml-based firewall bypass / port scanning vulnerability

2009-08-10 Thread Stefan Fritsch
On Monday 10 August 2009, Michael S Gilbert wrote: > it has been dislosed that apache (and potentially other web > servers) can be used to port scan behind a firewall. i don't think > this issue issue too severe, but a firewall bypass nevertheless is > probably not a good thing. see [0]. > > [0]

Bug#540862: apache2: xml-based firewall bypass / port scanning vulnerability

2009-08-10 Thread Michael S Gilbert
package: apache2 version: 2.2.3-4+etch6 severity: important tags: security it has been dislosed that apache (and potentially other web servers) can be used to port scan behind a firewall. i don't think this issue issue too severe, but a firewall bypass nevertheless is probably not a good thing.