Description
FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability.
Affected products
- Symantec / enterprise_firewall7.0 – 7.0
- Symantec / enterprise_firewall7.0 – 7.0
- Symantec / enterprise_firewall6.5.2 – 6.5.2
- Symantec / gateway_security1.0 – 1.0
- Symantec / raptor_firewall6.5 – 6.5
- Symantec / raptor_firewall6.5.3 – 6.5.3
- Symantec / velociraptor1.x – 1.x
References
- MISChttp://www.securityfocus.com/bid/4522
- MISChttp://archives.neohapsis.com/archives/bugtraq/2002-04/0166.html
- MISChttp://www.iss.net/security_center/static/8847.php
- MISChttp://archives.neohapsis.com/archives/bugtraq/2002-04/0224.html
- MISChttp://securityresponse.symantec.com/avcenter/security/Content/2002.04.17.html